Cross-Site Request Forgery Vulnerability in WP EasyPay – Square for WordPress
CVE-2021-4411
4.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 12 July 2023
What is CVE-2021-4411?
The WP EasyPay – Square for WordPress plugin is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in the wpep_download_transaction_in_excel() function. This vulnerability permits unauthenticated attackers to initiate a transaction download by deceiving site administrators into executing a malicious link, leading to potential unauthorized access and data exposure.
Affected Version(s)
WP EasyPay – Square for WordPress * <= 3.2.0