Bitcoin Donate Button WordPress Plugin Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Bitcoin Donate Button plugin for WordPress, affecting all versions through 1.0. The issue arises from inadequate nonce validation on the settings page, allowing unauthenticated attackers to alter the plugin's settings, such as donation addresses and display options. This can be achieved by tricking a site administrator into clicking a link that sends a forged request.
Impact
Exploitation of this vulnerability allows for unauthorized modification of the plugin's settings by an attacker, potentially leading to misdirected donations or altered display configurations on the site.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
