Cross-Site Request Forgery in WordPress Insert Headers And Footers Plugin to 3.1.1
The Insert Headers And Footers WordPress plugin (up to version 3.1.1) has a Cross-Site Request Forgery (CSRF) vulnerability in the 'custom_plugin_set_option' function. The vulnerability stems from missing or incorrect nonce validation, which allows unauthenticated attackers to update site options by tricking an administrator into performing a specific action like clicking a link. Attackers can potentially change the default registration role to administrator and enable user registration, ultimately gaining administrative access to the vulnerable WordPress site. However, the 'WPBRIGADE_SDK__DEV_MODE' constant must be set to 'true' to exploit this security weakness.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
hiddenpearls insert headers and footers |