WP Blast | SEO & Performance Booster <= 1.8.6 - Cross-Site Request Forgery to Cache Clearing
mediumThe WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.6. This is due to missing or incorrect nonce validation on multiple administrative actions in the Settings class. This makes it possible for unauthenticated attackers to tr...
- CVSS:
- 4.3
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.7
- Disclosed:
- Sep 9, 2025