CVE-2022-1618
- Reference to the description:
- Description:
- The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as escaping in their settings, allowing attacker to make a logged in admin add an arbitrary game with XSS payloads
- Last updated date:
- 08/29/2024
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 01/24/2024
- Reference url to background
https://wpscan.com/vulnerability/ddafcab2-b5db-4839-8ae1-188383f4250d/