Cross-Site Request Forgery in Estatebud WordPress Plugin Before 5.5.0
The Estatebud – Properties & Listings WordPress plugin has a Cross-Site Request Forgery (CSRF) vulnerability in all versions up to and including 5.5.0. The issue stems from a lack of proper nonce validation on the 'estatebud_settings' page. This weakness allows unauthenticated attackers to modify plugin settings by tricking a site administrator into performing a specific action, such as clicking a malicious link.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
estatebud estatebud – properties & listings |