CVE-2017-8099
Published Apr 24, 2017There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request.
Vendor archive
1 CVEs tagged to vendor browserweb_inc — 0 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request.