VYPR

Wp Orphanage Extended

by WordPress

Source repositories

CVEs (1)

  • CVE-2024-11415HigNov 23, 2024
    risk 0.57cvss 8.8epss 0.00

    The WP-Orphanage Extended plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the wporphanageex_menu_settings() function. This makes it possible for unauthenticated…