AI Image Lab WordPress Plugin Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the AI Image Lab – Free AI Image Generator plugin for WordPress, affecting all versions through 1.0.6. The vulnerability arises from inadequate nonce validation on the 'wpz-ai-images' admin page, allowing unauthenticated attackers to update the plugin's API key by sending a forged request, provided they can persuade a site administrator to click a link.
Impact
Exploitation of this vulnerability allows for Cross-Site Request Forgery, where an attacker can trick a user into performing actions they did not intend to, potentially leading to unauthorized changes in the WordPress site.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
