WebwinkelKeur <= 3.24 - Cross-Site Request Forgery
mediumThe WebwinkelKeur plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.24. This is due to missing nonce validation on the options_page() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can tr...
- CVSS:
- 4.3
- Affected:
- up to 3.25
- Fixed in:
- 3.25
- Disclosed:
- Jun 30, 2023