CVE-2022-1251
Ask Me < 6.8.4 - CSRF in Edit Profile
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.
Affected products
Unknown · Ask meWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →