PT-2019-5819 · WordPress · Arprice Lite

Published

2019-08-08

·

Updated

2019-08-19

·

CVE-2019-14679

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions ARPrice Lite plugin version 2.2 for WordPress
Description The issue is related to insufficient protection against CSRF requests in the ARPrice Lite plugin for WordPress. This can allow a remote attacker to perform a CSRF attack. The specific endpoint affected is "wp-admin/admin.php?page=arplite import export".
Recommendations For ARPrice Lite plugin version 2.2, consider implementing proper CSRF protection mechanisms to prevent exploitation. As a temporary workaround, restrict access to the "wp-admin/admin.php?page=arplite import export" endpoint to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03109
CVE-2019-14679

Affected Products

Arprice Lite