漏洞标题
WP Customer Area <= 8.2.4 版本中存在的 CSRF 漏洞导致批量删除问题
漏洞描述信息
WP Customer Area WordPress 插件在 8.2.4 及之前版本中,在某些地方缺少 CSRF(跨站请求伪造)检查,这可能允许攻击者利用 CSRF 攻击使已登录用户执行非预期操作。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
漏洞类别
跨站请求伪造(CSRF)
漏洞标题
WP Customer Area <= 8.2.4 - Bulk Delete via CSRF
漏洞描述信息
The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
CVSS信息
N/A
漏洞类别
N/A