Simple:Press
cpe:2.3:a:simple-press:simple:press:*:*:*:*:wordpress:*:*
- <= 6.10.11
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Simple:Press Forum plugin for WordPress, affecting all versions through 6.10.11. The vulnerability arises from inadequate nonce validation in the 'sp_save_edited_post' function, allowing unauthenticated attackers to alter forum posts by sending forged requests, provided they can deceive a site administrator into clicking a link.
Exploitation of this vulnerability could lead to unauthorized modification of forum posts by an attacker.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.