What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1.33.20.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1.33.20.
Explanation of Vulnerability in Simple Terms
WebinarPress versions up to 1.33.20 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the WebinarPress installation without the admin's knowledge or consent. The attacker has no special privileges and the victim must visit the malicious page, but successful exploitation can modify site data or disrupt service.
What an attacker can do
Trick a logged-in admin into visiting a malicious page that performs unwanted actions on WebinarPress.
Potential impact on your site
Administrators could unknowingly authorize changes to webinar settings, data, or configurations via CSRF attacks.
Conditions required to exploit
Victim must be logged in to WordPress and visit attacker-controlled webpage; no special privileges required.
Key dates
External resources
Related vulnerabilities