HomeDefault status
affected
Any version
affected
Description
The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
Any version
Credits
Daniel Ruf
WPScan
References
wpscan.com/...rability/72279ca0-6365-4c83-adca-4d8e5808a8c5/
wpscan.com/...rability/72279ca0-6365-4c83-adca-4d8e5808a8c5/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.