QID 150457
Date Published: 2022-01-27
QID 150457: WordPress Login/Signup Popup Plugin: CSRF Vulnerability (CVE-2022-0215)
Login/Signup Popup is a simple and light weight WordPress plugin which allow users to login/signup anywhere from the site with the simple pop up without refreshing page. Supported by Woocommerce.
In the installed version of the WordPress plugin, the "save_settings" function does not check for the "nonce", which could allow cross-site request forgery (CSRF) under some circumstances.
CSRF : Cross-site request forgery is a web security vulnerability that allows an attacker to induce users to perform actions that they do not intend to perform.
Affected Versions:
Login/Signup popup plugins before version 2.3
Successful exploitation of this vulnerability may allow remote attackers to update arbitrary options on a site that can be used to create an administrative user account and grant full privileged access to a compromised site.
Please refer to Wordfence security blog.
CVEs related to QID 150457
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Wordfence |
|