[Wordfence Alert] AliNext Lite version has a severe security vulnerability.
-
Description
The Ali2Woo Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform PHP Object Injection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.References
The page I need help with: [log in to see the link]
Viewing 4 replies - 1 through 4 (of 4 total)
Viewing 4 replies - 1 through 4 (of 4 total)
- You must be logged in to reply to this topic.