Tripetto WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Arbitrary Results Deletion

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Tripetto plugin for WordPress, affecting all versions through 8.0.9. The vulnerability arises from inadequate nonce validation, enabling unauthenticated attackers to delete arbitrary results by sending a forged request, provided they can deceive a site administrator into clicking a link.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of results within the Tripetto plugin.

Reproduction

To reproduce this vulnerability, an attacker must craft a forged request to delete results and trick an administrator into clicking a link that activates this request. This can be done by exploiting the lack of nonce validation in the plugin's result management features.

Remediation

Users are advised to update the Tripetto WordPress plugin to version 8.0.10 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
0.6
exploitability
7.6
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.