Website Monetization by MageNet <= 1.0.29.1 - Cross-Site Request Forgery via admin_magenet_settings
mediumThe Website Monetization by MageNet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.29.1. This is due to missing or incorrect nonce validation on the admin_magenet_settings function. This makes it possible for unauthenticated attackers to modify the plugin's settin...
- CVSS:
- 4.3
- Affected:
- up to 1.0.29.1
- Fixed in:
- 1.0.29.2
- Disclosed:
- Mar 16, 2023