Ask Me < 6.8.4 - CSRF in Edit Profile
CVE-2022-1251
4.3MEDIUM
What is CVE-2022-1251?
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request.
Affected Version(s)
Ask me 6.8.4