Tripetto
cpe:2.3:a:tripetto:tripetto:*:*:*:*:wordpress:*:*
- <= 8.0.9
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Tripetto plugin for WordPress, affecting all versions through 8.0.9. The vulnerability arises from inadequate nonce validation, enabling unauthenticated attackers to delete arbitrary results by sending a forged request, provided they can deceive a site administrator into clicking a link.
Exploitation of this vulnerability allows for unauthorized deletion of results within the Tripetto plugin.
To reproduce this vulnerability, an attacker must craft a forged request to delete results and trick an administrator into clicking a link that activates this request. This can be done by exploiting the lack of nonce validation in the plugin's result management features.
Users are advised to update the Tripetto WordPress plugin to version 8.0.10 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.