WP AutoBuzz
- <= 1.1.1
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP AutoBuzz plugin for WordPress, affecting all versions through 1.1.1. The issue arises from inadequate nonce validation, allowing unauthenticated attackers to manipulate settings and inject harmful web scripts by tricking a site administrator into clicking a link. This vulnerability circumvents WordPress's DISALLOW_UNFILTERED_HTML safeguard, as the unfiltered data is directly saved via the update_option function at the plugin level, bypassing WordPress's standard content management.
Exploitation of this vulnerability allows for Cross-Site Request Forgery, leading to stored Cross-Site Scripting. Malicious scripts injected into the 'googleAccount' parameter are executed in the context of the user.
No known patch is available. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.