CVE-2024-4480
WP Prayer II <= 2.4.7 - Email Settings Update via CSRF
The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L
Productos afectados
Unknown · WP Prayer II¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →