What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Julien Berthelot / MPEmbed.Com WP Matterport Shortcode allows Cross Site Request Forgery.This issue affects WP Matterport Shortcode: from n/a through 2.1.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Julien Berthelot / MPEmbed.Com WP Matterport Shortcode allows Cross Site Request Forgery.This issue affects WP Matterport Shortcode: from n/a through 2.1.9.
Explanation of Vulnerability in Simple Terms
WP Matterport Shortcode versions up to 2.1.9 are vulnerable to cross-site request forgery (CSRF). An attacker can trick a site administrator into performing unwanted actions—such as changing settings or embedding malicious content—by crafting a malicious link or page. The vulnerability requires the admin to click the link while logged in. No data is exposed, but site configuration can be altered without authorization.
What an attacker can do
Trick a logged-in admin into changing plugin settings or embedding unauthorized content via a crafted link.
Potential impact on your site
Plugin settings could be modified or malicious Matterport embeds added without your knowledge or consent.
Conditions required to exploit
Admin must click a malicious link while logged into the WordPress site.
Key dates
External resources
Related vulnerabilities