TNIT Filter Gallery Plugin <= 0.0.6 - Cross-Site Request Forgery to Cross-Site Scripting
mediumThe TNIT Filter Gallery Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions up to, and including, 0.0.6. This is due to improperly implemented nonce protection in several AJAX Calls. This makes it possible for unauthenticated attackers to gain otherwise restricted...
- CVSS:
- 6.1
- Affected:
- up to 0.0.6
- Fixed in:
- 0.0.7
- Disclosed:
- Jul 5, 2021