Vulnerabilities > Byonepress > Social Locker > 3.2.7

DATE CVE VULNERABILITY TITLE RISK
2019-09-26 CVE-2015-9425 Cross-Site Request Forgery (CSRF) vulnerability in Byonepress Social Locker
The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opanda-item&page=license-manager-sociallocker-next licensekey parameter.
4.3