vendor:
Curtain
by:
Hassan Khan Yusufzai - Splint3r7
8.8
CVSS
HIGH
Cross-site Request Forgery (CSRF)
352
CWE
Product Name: Curtain
Affected Version From: 1.0.2
Affected Version To: 1.0.2
Patch Exists: Yes
Related CWE:
CPE: 2.3:a:wordpress:curtain:1.0.2:*:*:*:*:*:*:*
Platforms Tested: Firefox
2022
WordPress Plugin Curtain 1.0.2 โ Cross-site Request Forgery (CSRF)
Cross site forgery vulnerability has been identified in curtain WordPress plugin that allows an attacker to to activate or deactivate sites maintenance mode.
Mitigation:
The vulnerability can be mitigated by updating the plugin to the latest version.