teachPress
cpe:2.3:a:teachpress_project:teachpress:*:*:*:*:wordpress:*:*
- <= 9.0.9
A Cross-Site Request Forgery (CSRF) vulnerability exists in the teachPress WordPress plugin, affecting all versions through 9.0.9. The issue arises from inadequate nonce validation on the import.php page, allowing unauthenticated attackers to delete imports by sending a forged request, provided they can persuade a site administrator to click a link or perform a similar action.
Exploitation of this vulnerability allows for Cross-Site Request Forgery, enabling attackers to delete imports without proper authorization.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.