Skip to content

CSRF Vulnerability via Patchstack #250

@georgeolaru

Description

@georgeolaru

There seems to be an issue regarding a missing WP Nonce which could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication.

Reference


@pixelgradebot whenever you have some free time, please take a look over this. Thanks!

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions