What the vulnerability does
01Description
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + Custom Post Types: from n/a through 1.0.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + Custom Post Types: from n/a through 1.0.2.
Explanation of Vulnerability in Simple Terms
Dashicons + Custom Post Types versions up to 1.0.2 lack proper authorization checks, allowing an attacker to modify site content if they can trick a logged-in user into visiting a malicious page. The vulnerability affects data integrity and availability but does not expose sensitive information. Site administrators should update to a version newer than 1.0.2.
What an attacker can do
Modify or delete site content if a logged-in user visits an attacker-controlled page.
Potential impact on your site
Site content can be altered or removed without proper authorization checks, requiring content restoration.
Conditions required to exploit
User interaction required; attacker must trick a logged-in user into visiting a malicious link or page.
Key dates
External resources
Related vulnerabilities