Multiple Themes by KlbTheme <= (Various Versions) - Cross-Site Request Forgery
mediumMultiple plugins and/or themes for WordPress by KlbTheme are vulnerable to Cross-Site Request Forgery in various versions. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site administ...
- CVSS:
- 4.3
- Affected:
- up to 1.1.6
- Fix:
- No patched version reported
- Disclosed:
- Dec 7, 2023