What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin <= 1.1.6 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Aftab Muni's Disable Right Click For WP plugin <= 1.1.6 at WordPress.
Explanation of Vulnerability in Simple Terms
The Disable Right Click For WP plugin through version 1.1.6 does not properly validate requests, allowing an attacker to perform unwanted actions on behalf of an authenticated user. An attacker can craft a malicious link or page that, when visited by a logged-in site administrator, modifies plugin settings or disables the right-click protection without the user's knowledge.
What an attacker can do
Modify plugin settings or disable right-click protection on a site by tricking a logged-in admin into visiting a malicious page.
Potential impact on your site
An attacker can change your plugin configuration without your consent, potentially disabling security features you rely on.
Conditions required to exploit
The site admin must be logged in and click a malicious link or visit an attacker-controlled page.
Key dates
External resources
Related vulnerabilities