VYPR

Duplicate Page Or Post

by Wpdevart

CVEs (1)

  • CVE-2021-25075LowFeb 21, 2022
    risk 0.23cvss 3.5epss 0.02

    The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in the wpdevart_duplicate_post_parametrs_save_in_db AJAX action, allowing any authenticated users, such as subscriber to call it and change the plugin's settings,…