Cross-Site Request Forgery in Top 10 WordPress Plugin by WordPress
CVE-2020-36761
4.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 12 July 2023
Summary
The Top 10 Plugin for WordPress is exposed to a Cross-Site Request Forgery vulnerability due to improper nonce validation in the tptn_export_tables() function. This weakness allows unauthenticated attackers to execute forged requests, potentially tricking site administrators into unwittingly exporting sensitive data. The exploitation occurs when the administrator clicks on a malicious link crafted by the attacker, thus compromising the site's integrity.
Affected Version(s)
Top 10 – Popular posts plugin for WordPress * < 2.9.5
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jerome Bruandet