WP Headers And Footers <= 3.1.1 - Cross-Site Request Forgery to Arbitrary Options Update
highThe Insert Headers And Footers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the 'custom_plugin_set_option' function. This makes it possible for unauthenticated attackers to update arbitrary options o...
- CVSS:
- 7.5
- Affected:
- up to 3.1.1
- Fixed in:
- 3.1.2
- Disclosed:
- Apr 18, 2025