Title Field Validation <= 1.1 - Cross-Site Request Forgery
high
The Title Field Validation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to add, edit, and delete validation parameters via a forged r...
- CVSS:
- 8.8
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Jun 30, 2021
Title Field Validation [title-field-validation] <= 1.1 (unfixed + closed)
unknown
The Title Field Validation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to add, edit, and delete validation parameters via a forged r...
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Jun 30, 2021
Title Field Validation [title-field-validation] <= 1.1 (unfixed + closed)
unknown
The plugin does not properly check for CSRF in its find_post_type, save_validation, edit_validation, update_validation and delete_validation AJAX actions. Additionally, the actions were also missing any capability checks. As a result, any authenticated user (such as subscriber) could call them to create, edit delete va...
- Affected:
- up to 1.1
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database