May 20, 2023, 3:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.8. This is due to missing nonce validation on the 'enable_safe_mode' function. This makes it possible for unauthenticated attackers to enable safe mode, which disables all other plugins, via a forged request if they can successfully trick an administrator into performing an action such as clicking on a link. A warning message about safe mode is displayed to the admin, which can be …

attackers cross-site cross-site request forgery cve enable forgery function missing mode nonce performing plugin plugins request safe safe mode validation vulnerable wordpress

Sr. Product Manager

@ MixMode | Remote, US

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Test Systems Design & Cybersecurity Engineer

@ Boeing | USA - El Segundo, CA

Cybersecurity Support Engineer (FortiClient) - Malaysia

@ Fortinet | Wilayah Persekutuan Kuala Lumpur, Malaysia