The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/311e3c15-0f58-4f3b-91f8-0c62c0eea55e/ | Exploit Third Party Advisory |
| https://wpscan.com/vulnerability/311e3c15-0f58-4f3b-91f8-0c62c0eea55e/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-07-30 06:15
Updated : 2026-01-02 20:19
NVD link : CVE-2024-6230
Mitre link : CVE-2024-6230
CVE.ORG link : CVE-2024-6230
JSON object : View
Products Affected
wp-master
- pardakht-delkhah
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
