Laiser Tag
- <= 1.2.5
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Laiser Tag plugin for WordPress, affecting all versions through 1.2.5. The issue arises from inadequate nonce validation in the addOptionsPageFields function, allowing unauthenticated attackers to manipulate the plugin's settings. This includes changes to the API key, tag blacklist, relevance threshold, batch size, and tagging toggles. Exploitation requires tricking a site administrator into clicking a link that initiates the forged request.
Exploitation of this vulnerability allows for unauthorized changes to the plugin's settings, potentially leading to misuse of the API key or other configuration options that could disrupt site functionality or security.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.