Exploits / Vulnerability Discovered : 2020-05-29 |
Type : webapps |
Platform : php
This exploit / vulnerability Wordpress plugin multischeduler 1.0.0 crosssite request forgery (delete user) is for educational purposes only and if it is used you will do on your own risk!
# 1. Technical Description:
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability
in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.