What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Scripting (XSS).This issue affects Complianz: from n/a through 6.4.4; Complianz Premium: from n/a through 6.4.6.1.
Explanation of Vulnerability in Simple Terms
02Summary
Complianz versions up to 6.4.4 contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to perform unauthorized actions on behalf of a logged-in site administrator. The vulnerability requires the admin to visit a malicious webpage while authenticated. An attacker can modify plugin settings, alter compliance configurations, or perform other administrative actions without the admin's knowledge.
What an attacker can do
03Attacker Capabilities
Perform administrative actions on the site (change settings, modify configurations) by tricking a logged-in admin into visiting a malicious page.
Potential impact on your site
04Site Impact
An attacker can alter Complianz settings and compliance configurations without your permission if you click a malicious link while logged in.
Conditions required to exploit
05Prerequisites
Site admin must be logged in and visit a page controlled by the attacker (e.g., via a malicious link or email).
Key dates
06Disclosure timeline
November 30, 2023
CVE published
April 28, 2026
Record updated