AMO.CRM WordPress Plugin Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the AMO.CRM integration WordPress plugin, affecting all versions up to and including 1.0.1. The vulnerability arises from inadequate nonce validation in the 'settings_page' function, allowing unauthenticated attackers to alter essential API connection settings. This includes the AMO.CRM API URL, login credentials, and API hash key, by sending a forged request that tricks a site administrator into clicking a link.
Impact
Exploitation allows for unauthorized modification of API connection settings, potentially leading to unauthorized access or actions within the AMO.CRM integration.
Remediation
No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
