What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF), Incorrect Authorization vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.3.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF), Incorrect Authorization vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.3.7.
Explanation of Vulnerability in Simple Terms
Legal Pages for WordPress contains a cross-site request forgery (CSRF) vulnerability in versions up to 1.3.7. An attacker with low-level site access can craft a malicious request that, when visited by an authenticated administrator, modifies site settings or content without the admin's knowledge. The vulnerability requires no user interaction from the attacker but does require the admin to visit a malicious page.
What an attacker can do
Modify site settings or content by tricking an authenticated admin into visiting a malicious page.
Potential impact on your site
An attacker with subscriber access can alter your site's legal pages or settings without your consent by exploiting admin sessions.
Conditions required to exploit
Attacker needs low-level site access (e.g., subscriber account). Admin must visit attacker-controlled page while logged in.
Key dates
External resources
Related vulnerabilities