RSS   Vulnerabilities for
'Digital publications by supsystic'
   RSS

2023-12-09
 
CVE-2023-5756

CWE-352
 

 
The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

 

 >>> Vendor: Supsystic 10 Products
Popup
Newsletter by supsystic
Pricing table by supsystic
Data tables generator
Contact form
Ultimate maps
Easy google maps
Price table
Social share buttons
Digital publications by supsystic


Copyright 2024, cxsecurity.com

 

Back to Top