CVE Published: 11/07/2023 |
CVE Updated: 08/11/2024 |
CVE Year: 2023 Source: Wordfence |
Vendor: buymeacoffee |
Product: Buy Me a Coffee – Button and Widget Plugin Status : PUBLISHED
CVE-2023-2079 Description
The "Buy Me a Coffee – Button and Widget Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the recieve_post, bmc_disconnect, name_post, and widget_post functions in versions up to, and including, 3.7. This makes it possible for unauthenticated attackers to update the plugins settings, via a forged request granted the attacker can trick a site\'s administrator into performing an action such as clicking on a link.
Metrics
CVSS Version: 3.1 |
Base Score: 8.3 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L