Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Workreap theme < 2.2.2 - Multiple CSRF + IDOR Vulnerabilities
Vulnerability Description
Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct object references that were not validated. This allows an attacker to trick a logged in user to submit a POST request to the vulnerable site, potentially modifying or deleting arbitrary objects on the target site.
CVSS Information
N/A
Vulnerability Type
未经验证的属主
Vulnerability Title
WordPress 跨站请求伪造漏洞
Vulnerability Description
WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress Workreap theme 2.2.2之前版本存在安全漏洞,该漏洞源于插件中可用的几个AJAX操作缺乏CSRF保护,并允许未经验证的不安全直接对象引用。
CVSS Information
N/A
Vulnerability Type
N/A