The Fatal Error Notify WordPress... CVE-2023-7202

- AV AC AU C I A
发布: 2024-02-27
修订: 2024-02-27

The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such as subscriber to call it and spam the admin email address with error messages. The issue is also exploitable via CSRF

0%
暂无可用Exp或PoC
当前有0条受影响产品信息