CVE-2024-4969 Information
Jun 22, 2024
cve
Description
The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets which could allow attackers to make logged in admin enable/disable widgets via a CSRF attack
Reference
https://wpscan.com/vulnerability/1a7ec5dc-eda4-4fed-9df9-f41d2b937fed/
Share on: