WP Customer Area
cpe:2.3:a:wp-customerarea:wp_customer_area:*:*:*:*:wordpress:*:*
- < 8.2.5
A cross-site request forgery (CSRF) vulnerability has been identified in the WP Customer Area WordPress plugin, affecting versions through 8.2.4. The vulnerability arises because the plugin does not implement CSRF protection when logs are deleted. This lack of protection could enable attackers to exploit a logged-in user to delete logs on their behalf.
Exploitation of this vulnerability allows for unauthorized log deletion, potentially leading to loss of important event data.
Users can update to WP Customer Area version 8.2.5 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.