What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Mass Delete Unused Tags plugin <= 2.0.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Ramon Fincken Mass Delete Unused Tags plugin <= 2.0.0 versions.
Explanation of Vulnerability in Simple Terms
Mass Delete Unused Tags contains a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unwanted tag deletion actions on behalf of an authenticated user. The vulnerability requires user interaction—the victim must visit a malicious page while logged into their site. An attacker cannot read sensitive data but can modify or delete tags without authorization.
What an attacker can do
Delete or modify tags on the site by tricking a logged-in user into visiting a malicious page.
Potential impact on your site
Tags can be deleted without your knowledge or consent if you visit a compromised site while logged in.
Conditions required to exploit
Victim must be logged in and click a malicious link or visit an attacker-controlled page.
Key dates
External resources
Related vulnerabilities