The ClickBank Affiliate Ads WordPress plugin through 1.20...
Critical severity
Unreviewed
Published
Dec 3, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Dec 2, 2021
Published to the GitHub Advisory Database
Dec 3, 2021
Last updated
Feb 1, 2023
The ClickBank Affiliate Ads WordPress plugin through 1.20 does not have CSRF check when saving its settings, allowing attacker to make logged in admin change them via a CSRF attack. Furthermore, due to the lack of escaping when they are outputting, it could also lead to Stored Cross-Site Scripting issues
References