auto_plugin_install AJAX action, which makes it possible for attackers to install and activate arbitrary plugins from WordPress.org repository via a forged request if they can trick an administrator into performing an action such as clicking on a link. Uncanny Toolkit for LearnDash <= 3.6.4.1 - Cross-Site Request Forgery (CSRF) to Arbitrary Plugin Installation
REPORT ID: ae4d66a3-28fe-4b27-8aa3-60646cf1ccef
The plugin contains a Cross-Site Request Forgery (CSRF) vulnerability due to a missing nonce check in the
You need to log in to view the vulnerability details.