What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Sandor Kovacs Regenerate post permalink allows Cross-Site Scripting (XSS).This issue affects Regenerate post permalink: from n/a through 1.0.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Sandor Kovacs Regenerate post permalink allows Cross-Site Scripting (XSS).This issue affects Regenerate post permalink: from n/a through 1.0.3.
Explanation of Vulnerability in Simple Terms
The Regenerate post permalink plugin through version 1.0.3 is vulnerable to cross-site request forgery (CSRF). An attacker can trick a site administrator into visiting a malicious page that performs unauthorized actions on the site, such as regenerating post permalinks. The vulnerability requires user interaction and can affect the site's integrity and availability.
What an attacker can do
Trick an admin into visiting a malicious page to perform unauthorized actions like regenerating post permalinks.
Potential impact on your site
Attackers can manipulate post permalinks and other site settings if an admin visits a malicious link.
Conditions required to exploit
Admin must visit attacker-controlled page; no authentication bypass needed.
Key dates
External resources
Related vulnerabilities