Alfie
- <= 1.2.1
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Alfie – Feed Plugin for WordPress, affecting all versions through 1.2.1. The issue arises from a lack of nonce validation in the 'alfie_manage()' function, which is responsible for deleting feeds via the 'delete' GET parameter. This vulnerability allows unauthenticated attackers to remove arbitrary feed data from several plugin tables, provided they can deceive a site administrator into clicking a link that triggers the deletion.
Exploitation of this vulnerability allows for Cross-Site Request Forgery, enabling the deletion of plugin feed data from multiple tables.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.