Bulk Page Creator <= 1.1.3 - Cross-Site Request Forgery to Arbitrary Page Creation

2022-05-09 00:00
Daniel Ruf

Strategic Overview

Status
Patched in 1.1.4
Affected PluginBulk Page Creator
Affected Version<= 1.1.3
CVSS8.8High
CVECVE-2022-1611
View all Bulk Page Creator vulnerabilities

Vulnerability Overview

The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks, which makes them vulnerable to CSRF.

Technical Analysis

REMEDIATION: Update to version 1.1.4, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C