Appsero <= 1.2.0 - Cross-Site Request Forgery
mediumThe Appsero analytics tool used in several plugins is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the uninstall_reason_submission function used for feedback submission in versions up to, and including, 1.2.0. This makes it possible for unauthenticated attackers to invoke this function inten...
- CVSS:
- 4.3
- Affected:
- up to 1.0.6
- Fixed in:
- 2.0.0
- Disclosed:
- Dec 14, 2022