Back
WordPress Contextual Related Posts plugin <= 2.9.3 - Cross-Site Request Forgery (CSRF) Nonce Validation Bypass vulnerability
- Product
- Contextual Related Posts
- Description
- Cross-Site Request Forgery (CSRF) Nonce Validation Bypass vulnerability found by Lenon Leite in WordPress Contextual Related Posts plugin (versions <= 2.9.3).
- Solution
- Update the WordPress Contextual Related Posts plugin to the latest available version (at least 2.9.3).
- Classification
-
Type Cross Site Request Forgery (CSRF)
OWASP Top 10 A2: Broken Authentication and Session Management
- References
-
Plugin changelog
- CVE
- Name CVE-N/A
- Versions
-
Affected In
<= 2.9.3
Fixed In 2.9.4
- Disclosure date
- 2020-11-19
- Credits
- Lenon Leite