The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://wpvulndb.com/vulnerabilities/8706 | third party advisory exploit |
https://wordpress.org/plugins/copy-me/#developers | product |
https://advisories.dxw.com/advisories/copy-me-vulnerable-to-csrf-allowing-unauthenticated-attacker-to-copy-posts/ | third party advisory exploit |