Conversation
supportJust looking around for a good PDF creator and found this. However, I see there is an issue flagged by Wordfence, that it is “… vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.0 … due to missing or incorrect nonce validation on a function”. The link is below. I see the current version here is the same as the one they flagged (1.2.0). Further description includes “This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.” https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/nopeamedia/print-pdf-generator-and-publisher-120-cross-site-request-forgery Thanks so much for any advice on this issue.
No comments were stored for this source.