Zawgyi Embed WordPress Plugin Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Zawgyi Embed plugin for WordPress, affecting all versions through 2.1.1. The issue arises from inadequate nonce validation in the 'zawgyi_adminpage' function, allowing unauthenticated attackers to manipulate the 'zawgyi_forceCSS' setting. Exploitation involves sending a forged POST request to 'options-general.php?page=zawgyi_embed', tricking a site administrator into clicking a link that activates the request.
Impact
Exploitation of this vulnerability allows for Cross-Site Request Forgery, where an attacker can impersonate a user and perform actions on their behalf without their consent.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
