Vulnerabilities > Adamsolymosi

DATE CVE VULNERABILITY TITLE RISK
2024-07-12 CVE-2024-6022 Cross-Site Request Forgery (CSRF) vulnerability in Adamsolymosi Contentlock 1.0.2/1.0.3
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
network
low complexity
adamsolymosi CWE-352
8.8
2024-07-12 CVE-2024-6023 Cross-Site Request Forgery (CSRF) vulnerability in Adamsolymosi Contentlock 1.0.2/1.0.3
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in admin perform such action via a CSRF attack
network
low complexity
adamsolymosi CWE-352
8.8