The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, which could allow attackers to make a logged in admin remove arbitrary bans
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/d4c32a02-810f-43d8-946a-b7e18ac54f55 | third party advisory exploit |
https://plugins.trac.wordpress.org/changeset/2705068 | third party advisory patch |