What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows Privilege Escalation.This issue affects User Profile Meta Manager: from n/a through <= 1.02.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows Privilege Escalation.This issue affects User Profile Meta Manager: from n/a through <= 1.02.
Explanation of Vulnerability in Simple Terms
User Profile Meta Manager versions 1.02 and earlier contain a cross-site request forgery (CSRF) vulnerability that allows unauthenticated attackers to perform unauthorized actions on affected sites without user interaction. An attacker can craft a malicious request that, when processed by the vulnerable plugin, modifies user profile data or other site settings. This vulnerability requires no special privileges or user interaction to exploit.
What an attacker can do
Perform unauthorized actions on the site, such as modifying user profiles or settings, without authentication.
Potential impact on your site
User profile data and site settings can be altered by remote attackers without your knowledge or consent.
Conditions required to exploit
The vulnerable plugin must be installed and active; no user authentication or interaction required.
Key dates
External resources
Related vulnerabilities