WordPress PHP Everywhere plugin <= 2.0.2 - Cross-Site Request Forgery (CSRF) vulnerability
Vulnerable versions
<= 2.0.2
PSID
36abdbf775fb
Classification
Cross Site Request Forgery (CSRF)
OWASP Top 10
A5: Broken Access Control
Required privilege
Publicly disclosed
2021-12-23
Patchstack vPatch available since
09.12.2021
Details
Cross-Site Request Forgery (CSRF) vulnerability discovered by Rasi Afeef in WordPress PHP Everywhere plugin (versions <= 2.0.2).
Solution
Update the WordPress PHP Everywhere plugin to the latest available version (at least 2.0.3).
References
Plugin changelog
CVE-2021-23227