The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CSRF checks, and is vulnerable to a CSRF attack
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/3351bc30-e5ff-471f-8d1c-b1bcdf419937 | third party advisory exploit |
https://jetpack.com/2021/09/14/csrf-vulnerability-found-in-software-license-manager-plugin/ | third party advisory exploit |