Useful Banner Manager <= 1.6.1 - Modify banners via CSRF
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
The Useful Banner Manager WordPress plugin through 1.6.1 does not perform CSRF checks on POST requests to its admin page, allowing an attacker to trick a logged in admin to add, modify or delete banners from the plugin by submitting a form.
Affected products
Unknown · Useful Banner Manager