The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://zeroauth.ltd/blog/ | third party advisory exploit |
https://wordpress.org/plugins/marketo-forms-and-tracking/#developers | vendor advisory |
https://wpvulndb.com/vulnerabilities/10031 | third party advisory |