WP Performance Score Booster <= 2.0 - Settings Change via Cross-Site Request Forgery
mediumThe WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
- CVSS:
- 4.3
- Affected:
- up to 2.0
- Fixed in:
- 2.1
- Disclosed:
- Oct 18, 2021