Vulnerability: Authenticated Stored XSS/CSRF
-
CSRF/stored XSS in WordPress Firewall 2 allows unauthenticated attackers to do almost anything an admin can
More information via: https://security.dxw.com/advisories/csrfstored-xss-in-wordpress-firewall-2-allows-unauthenticated-attackers-to-do-almost-anything-an-admin-can/
As plugin developer seemingly cannot be contacted, best will be to deactivate and remove the plugin and look for an alternative elsewhere.
- The topic ‘Vulnerability: Authenticated Stored XSS/CSRF’ is closed to new replies.