a3 Lazy Load <= 2.6.0 - Cross-Site Request Forgery to Settings Reset
high
The following plugins for WordPress are vulnerable to Cross-Site Request Forgery:
a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...
- CVSS:
- 8.8
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.2
- Disclosed:
- Nov 2, 2022
Product Widget Slider for WooCommerce [woo-widget-product-slideshow] < 1.9.2
unknown
The following plugins for WordPress are vulnerable to Cross-Site Request Forgery:
a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- Nov 2, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database