Vulnerabilities > Getperfectsurvey > Perfect Survey > High

DATE CVE VULNERABILITY TITLE RISK
2022-02-01 CVE-2021-24763 Cross-Site Request Forgery (CSRF) vulnerability in Getperfectsurvey Perfect Survey
The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing unauthenticated users to edit surveys and modify settings.
network
low complexity
getperfectsurvey CWE-352
8.8