WP Simple Adsense Insertion < 2.1 - Inject ads and javascript via CSRF
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via submitting a form.
Affected products
Unknown · WP Simple Adsense Insertion