PT-2025-37147 · Izem+1 · Run Log
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Run Log plugin for WordPress versions prior to 1.7.11
Description
Cross-Site Request Forgery occurs due to missing or incorrect nonce validation in the
oirl plugin options() function. A nonce is a unique token used to protect against forged requests. This allows unauthenticated attackers to modify plugin settings, such as distance units, pace display preferences, style themes, and display positions, by tricking a site administrator into clicking a malicious link.Recommendations
Update the plugin to a version later than 1.7.10.
As a temporary mitigation, restrict administrative access to the plugin settings until the update is applied.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Run Log