Acunetix WP Security <= 4.0.4 - Cross-Site Request Forgery
highThe Acunetix WP Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.4. This is due to missing or incorrect nonce validation in the ~/box-database-backup.php file. This makes it possible for unauthenticated attackers to trigger a database back-up via a forged r...
- CVSS:
- 8.8
- Affected:
- up to 4.0.5
- Fixed in:
- 4.0.5
- Disclosed:
- Feb 11, 2014