PT-2019-5819 · WordPress · Arprice Lite
Published
2019-08-08
·
Updated
2019-08-19
·
CVE-2019-14679
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
ARPrice Lite plugin version 2.2 for WordPress
Description
The issue is related to insufficient protection against CSRF requests in the ARPrice Lite plugin for WordPress. This can allow a remote attacker to perform a CSRF attack. The specific endpoint affected is "wp-admin/admin.php?page=arplite import export".
Recommendations
For ARPrice Lite plugin version 2.2, consider implementing proper CSRF protection mechanisms to prevent exploitation.
As a temporary workaround, restrict access to the "wp-admin/admin.php?page=arplite import export" endpoint to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arprice Lite