cleantalk
Vulnerabilities and Security Researches

Bing Custom Search for WordPress, b7d9c54a-9a9a-48ad-bb78-e30340963236

Published on
-
Research Description
Bing Custom Search for WordPress [wp-bing-search] < 2.4 Unauthorised AJAX Calls via Freemius The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a CSRF attack.
Affected versions
max 2.4.
Status
vulnerable