Request for Quote < 1.3 - Cross-Site Request Forgery
highThe Request for Quote plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.3. This is due to missing or incorrect nonce validation in the action_wpheka_add_to_quote and action_remove_item_from_rfq_list AJAX actions. This makes it possible for unauthenticated attackers to perform restric...
- CVSS:
- 8.8
- Affected:
- up to 1.3
- Fixed in:
- 1.3
- Disclosed:
- Jul 5, 2021