PT-2025-37152 · Jegerwan+1 · Plugin Updates Blocker
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Plugin updates blocker for WordPress versions prior to 0.3
Description
Cross-Site Request Forgery occurs due to missing or incorrect nonce validation—a security token used to prevent forged requests—on the
pub save action handler. This allows unauthenticated attackers to enable or disable plugin updates by tricking a site administrator into clicking a malicious link.Recommendations
Update the plugin to a version later than 0.2.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plugin Updates Blocker