wo_regenerate_secret AJAX action, which makes it possible for attackers to regenerate the secret of an arbitrary client via a forged request if they can trick an administrator into performing an action such as clicking on a link. WP OAuth Server by Justin Greer <= 3.4.1 - Cross-Site Request Forgery (CSRF) to Client Secret Regeneration
REPORT ID: ca7d2c22-e74d-4584-8a14-204e54b34b71
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the
You need to log in to view the vulnerability details.