WP RSS Multi Importer < 3.14 - Cross-Site Request Forgery
highThe WP RSS Multi Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 3.14. This is due to missing nonce validation on several GET request functions. This makes it possible for unauthenticated attackers to perform restricted actions, such as arbitrary post deletion, via forged req...
- CVSS:
- 8.8
- Affected:
- up to 3.14
- Fixed in:
- 3.14
- Disclosed:
- Sep 17, 2014