What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in ThemeKraft TK Google Fonts GDPR Compliant plugin <= 2.2.11 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in ThemeKraft TK Google Fonts GDPR Compliant plugin <= 2.2.11 versions.
Explanation of Vulnerability in Simple Terms
TK Google Fonts GDPR Compliant versions up to 2.2.11 contain a cross-site request forgery (CSRF) vulnerability. An attacker can trick a site administrator into performing unintended actions by visiting a malicious webpage while logged in. The vulnerability allows modification of plugin settings without proper verification. Update to a version newer than 2.2.11 to resolve this issue.
What an attacker can do
Trick a logged-in admin into changing plugin settings via a malicious webpage.
Potential impact on your site
Plugin settings can be altered without your knowledge if you click a malicious link while logged in.
Conditions required to exploit
Admin must be logged in and visit attacker-controlled page; no special privileges required.
Key dates
External resources
Related vulnerabilities