Loading vulnerability details…
CVSS v3.1
7.6
EPSS
0.26%
Published
Jun 26, 2024
Modified
May 19, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:LWeaknesses (CWE)
Affected Products (1)
References (2)