CVE-2022-3149

CVE-2022-3149

The WP Custom Cursors WordPress plugin before 3.0.1 does not have CSRF check in place when creating and editing cursors, which could allow attackers to made a logged in admin perform such actions via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping in some of the cursor options, it could also lead to Stored Cross-Site Scripting

Source: CVE-2022-3149

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다