The Woody code snippets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.9. This is due to missing or incorrect nonce validation on the runActions() function. This makes it possible for unauthenticated attackers to activate and deactivate snippets via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
More Stories
kernel-6.6.3-200.fc39 kernel-headers-6.6.3-200.fc39 kernel-tools-6.6.3-200.fc39
FEDORA-2023-a7b89262c6 Packages in this update: kernel-6.6.3-200.fc39 kernel-headers-6.6.3-200.fc39 kernel-tools-6.6.3-200.fc39 Update description: The 6.6.3 stable kernel update contains a number of important...
kernel-6.6.3-100.fc38 kernel-headers-6.6.3-100.fc38 kernel-tools-6.6.3-100.fc38
FEDORA-2023-15deb2e32a Packages in this update: kernel-6.6.3-100.fc38 kernel-headers-6.6.3-100.fc38 kernel-tools-6.6.3-100.fc38 Update description: The 6.6.3 stable kernel update contains a number of important...
USN-6502-3: Linux kernel (NVIDIA) vulnerabilities
Ivan D Barrera, Christopher Bednarz, Mustafa Ismail, and Shiraz Saleem discovered that the InfiniBand RDMA driver in the Linux kernel...
USN-6520-1: Linux kernel (StarFive) vulnerabilities
Ivan D Barrera, Christopher Bednarz, Mustafa Ismail, and Shiraz Saleem discovered that the InfiniBand RDMA driver in the Linux kernel...
gmailctl-0.10.7-1.fc39
FEDORA-2023-e3e4e3f51a Packages in this update: gmailctl-0.10.7-1.fc39 Update description: upgrade to v0.10.7, CVE-2023-39325 Read More
gmailctl-0.10.7-1.fc38
FEDORA-2023-6f4c5b6331 Packages in this update: gmailctl-0.10.7-1.fc38 Update description: upgrade to v0.10.7, close rhbz#2249798 Read More