Cross-Site Request Forgery in Top 10 WordPress Plugin by WordPress
CVE-2020-36761

4.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
12 July 2023

Summary

The Top 10 Plugin for WordPress is exposed to a Cross-Site Request Forgery vulnerability due to improper nonce validation in the tptn_export_tables() function. This weakness allows unauthenticated attackers to execute forged requests, potentially tricking site administrators into unwittingly exporting sensitive data. The exploitation occurs when the administrator clicks on a malicious link crafted by the attacker, thus compromising the site's integrity.

Affected Version(s)

Top 10 – Popular posts plugin for WordPress * < 2.9.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jerome Bruandet
.