cleantalk
Vulnerabilities and Security Researches

WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout, de469805798894de73033621e14693d94a7e0dcc

Published on
Mar 22, 2023
Research Description
WordPress Pinterest Plugin &#8211; Make a Popup, User Profile, Masonry and Gallery Layout [gs-pinterest-portfolio] < 1.6.2 WordPress GS Pins for Pinterest Plugin <= 1.6.2 is vulnerable to Cross Site Request Forgery (CSRF) No patched version is available. No reply from the vendor. Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress GS Pins for Pinterest Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has not been known to be fixed yet.
Affected versions
max 1.6.2.
Status
vulnerable