pixelgrade / customify

Intuitive Website Styling integrated into WordPress' Customizer
GNU General Public License v2.0
28 stars 5 forks source link

CSRF Vulnerability via Patchstack #250

Closed georgeolaru closed 1 year ago

georgeolaru commented 1 year ago

There seems to be an issue regarding a missing WP Nonce which could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication.

Reference


@pixelgradebot whenever you have some free time, please take a look over this. Thanks!