mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-05 18:27:17 +00:00
20 lines
1.4 KiB
Markdown
20 lines
1.4 KiB
Markdown
![]() |
### [CVE-2023-2407](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2407)
|
|||
|

|
|||
|

|
|||
|

|
|||
|

|
|||
|
&color=brighgreen)
|
|||
|
|
|||
|
### Description
|
|||
|
|
|||
|
The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
|
|||
|
|
|||
|
### POC
|
|||
|
|
|||
|
#### Reference
|
|||
|
- https://blog.jonh.eu/blog/security-vulnerabilities-in-wordpress-plugins-by-vcita
|
|||
|
|
|||
|
#### Github
|
|||
|
No PoCs found on GitHub currently.
|
|||
|
|