WPIntell

Source evidence

CSRF vulnerability

Manage Notification E-mails · support · 2022-09-28T02:28:00+00:00

complaintsentiment
highseverity
0.9relevance
4replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 34 rows with source links

14.7% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
dstamos unresolved
I get the following Message about your plugin saying that your plugin has a vulnerability. Is this true and if so when will the vulnerability be fixed? Please Advise ASAP. WordPress Manage Notification E-mails plugin <= 1.8.2 – Cross-Site Request Forgery (CSRF) vulnerability +1 Thank you. We get the same warning as well and we use this plugin for every website we own. WordPress Manage Notification E-mails plugin <= 1.8.2 – Cross-Site Request Forgery (CSRF) vulnerability. This reply was modified 3 years, 8 months ago by Yui . This reply was modified 3 years, 8 months ago by sexcuk . I wish the problem report had more information. I did look into this a bit to see if it could be mitigated with a hotfix, but I only see $_POST data being evaluated in one location, and in that location checks are made for both current_user_can() as well as check_admin_referrer(). But this isn’t my area so there may yet be some other security hole in here. 1.8.3 is out to fix this. Quick response! Thanks!!

Comments

4 shown
Idel 2022-09-28T05:17:00+00:00

+1 Thank you.

sexcuk 2022-09-28T07:40:00+00:00

We get the same warning as well and we use this plugin for every website we own. WordPress Manage Notification E-mails plugin <= 1.8.2 – Cross-Site Request Forgery (CSRF) vulnerability. This reply was modified 3 years, 8 months ago by Yui . This reply was modified 3 years, 8 months ago by sexcuk .

scmsteve 2022-09-28T16:16:00+00:00

I wish the problem report had more information. I did look into this a bit to see if it could be mitigated with a hotfix, but I only see $_POST data being evaluated in one location, and in that location checks are made for both current_user_can() as well as check_admin_referrer(). But this isn’t my area so there may yet be some other security hole in here.

scmsteve 2022-09-28T19:45:00+00:00

1.8.3 is out to fix this. Quick response! Thanks!!