The Crisp Live Chat WordPress plugin is vulnerable to...
High severity
Unreviewed
Published
Jan 19, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Jan 18, 2022
Published to the GitHub Advisory Database
Jan 19, 2022
Last updated
Feb 3, 2023
The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page function found in the ~/crisp.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 0.31.
References