RSS   Vulnerabilities for 'Mass pages/posts creator'   RSS

2018-05-30
 
CVE-2018-11580

CWE-79
 

 
An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce or user capability check, so anyone can launch a DoS attack against a site and create hundreds of thousands of posts with custom content.

 

 >>> Vendor: Multidots 6 Products
Woo checkout for digital goods
Add social share messenger buttons whatsapp and viber
Woocommerce quick reports
Advance search for woocommerce
Woocommerce category banner management
Mass pages/posts creator


Copyright 2019, cxsecurity.com

 

Back to Top