99fy_ajax_plugin_activation AJAX action, which makes it possible for attackers to activate arbitrary plugins present on the blog via a forged request if they can trick an administrator into performing an action such as clicking on a link. Free WooCommerce Theme 99fy Extension by HasThemes <= 1.2.7 - Cross-Site Request Forgery (CSRF) to Arbitrary Plugin Activation
REPORT ID: 8fd2fd5d-bebd-4d1e-b09c-ce5db9a2b1c4
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the
You need to log in to view the vulnerability details.