RSS   Vulnerabilities for 'Duplicate page or post'   RSS

2022-02-21
 
CVE-2021-25075

CWE-862
 

 
The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings, or perform such attack via CSRF. Furthermore, due to the lack of escaping, this could lead to Stored Cross-Site Scripting issues

 

 >>> Vendor: Wpdevart 10 Products
Responsive image gallery gallery album
Booking calendar
Poll\, survey\, questionnaire and voting system
Youtube embed\, playlist and popup
Countdown and countup\, woocommerce sales timer
Coming soon and maintenance mode
Duplicate page or post
Pricing table builder
Social comments
Gallery


Copyright 2024, cxsecurity.com

 

Back to Top