Loading vulnerability details…
CVSS v3.1
6.1
EPSS
0.20%
Published
Jun 14, 2024
Modified
May 12, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:LWeaknesses (CWE)
Affected Products (1)
References (2)