cleantalk
Vulnerabilities and Security Researches

Custom Field Template, aa47a464-af97-43bc-b6cb-75a08ce3ece7

Application

Custom Field Template

Published on
-
Research Description
Custom Field Template [custom-field-template] < 2.5.2 Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF) NinTechNet discovered multiple WordPress plugins and themes vulnerable to Cross-Site Request Forgery (CSRF). The items only check the CSRF nonce if it has been provided, making them vulnerable to CSRF attacks if the nonce is removed. This is due to the confusing use of logic operators when verifying the nonces.
Affected versions
max 2.5.2.
Status
vulnerable