Extend Themes <= (Multiple Versions) - Cross-Site Request Forgery
mediumSeveral Extend Themes themes for WordPress are vulnerable to Cross-Site Request Forgery in multiple versions. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into p...
- CVSS:
- 4.3
- Affected:
- up to 1.0.10
- Fixed in:
- 1.0.11
- Disclosed:
- May 13, 2024