Vulnerabilities > Shantz Wordpress Qotd Project

DATE CVE VULNERABILITY TITLE RISK
2021-08-16 CVE-2021-24380 Cross-Site Request Forgery (CSRF) vulnerability in Shantz Wordpress Qotd Project Shantz Wordpress Qotd
The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing attackers to make logged in administrators change them to arbitrary values.
network
low complexity
shantz-wordpress-qotd-project CWE-352
4.3