← back
CVE-2022-1695

WP Simple Adsense Insertion < 2.1 - Inject ads and javascript via CSRF

EPSS 0.4%CWE-352
The WP Simple Adsense Insertion WordPress plugin before 2.1 does not perform CSRF checks on updates to its admin page, allowing an attacker to trick a logged in user to manipulate ads and inject arbitrary javascript via submitting a form.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →