vendor:
Fitness Calculators
by:
0xB9
4,3
CVSS
MEDIUM
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Fitness Calculators
Affected Version From: 1.9.5
Affected Version To: 1.9.5
Patch Exists: YES
Related CWE: CVE-2021-24272
CPE: a:wordpress:fitness_calculators
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10
2021
WordPress Plugin Fitness Calculators 1.9.5 – Cross-Site Request Forgery (CSRF)
The plugin add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the calculator headers. Due to the lack of sanitisation, this could also lead to a Stored Cross-Site Scripting issue.
Mitigation:
The vendor has released a patch to address this issue. Users should update to version 1.9.6 or later.