WP VK-付费内容插件(付费阅读/资料/工具软件资源管理) [wp-vk] < 1.3.4
unknown
Update the WordPress WP VK plugin to the latest available version (at least 1.3.4).
WordFence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress WP VK Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authen...
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Aug 24, 2023
WP VK-付费内容插件 <= 1.3.3 - Cross-Site Request Forgery via AJAX actions
medium
The WP VK-付费内容插件 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.3. This is due to missing or incorrect nonce validation on several of its AJAX actions. This makes it possible for unauthenticated attackers to update plugin settings via a forged request grante...
- CVSS:
- 4.3
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Aug 23, 2023
WP VK-付费内容插件(付费阅读/资料/工具软件资源管理) [wp-vk] < 1.3.4
unknown
The WP VK-付费内容插件 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.3. This is due to missing or incorrect nonce validation on several of its AJAX actions. This makes it possible for unauthenticated attackers to update plugin settings via a forged request grante...
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Aug 23, 2023
WP VK-付费内容插件(付费阅读/资料/工具软件资源管理) [wp-vk] < 1.3.4
unknown
The plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.3. This is due to missing or incorrect nonce validation on several of its AJAX actions. This makes it possible for unauthenticated attackers to update plugin settings via a forged request granted they can trick a site administr...
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database