Events Rich Snippets for Google <= 1.8 - Cross-Site Request Forgery to Arbitrary Options Update
highThe Events Rich Snippets for Google plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8. This is due to missing or incorrect nonce validation on the handleEventSettings() function. This makes it possible for unauthenticated attackers to update arbitrary options which c...
- CVSS:
- 8.8
- Affected:
- up to 1.8
- Fix:
- No patched version reported
- Disclosed:
- Sep 28, 2023