12 Aug 2019

Vulnerability Details: Privilege Escalation in WP Social Feed Gallery

One of the change log entries for the latest version of the plugin WP Social Feed Gallery is “Fix. nonce validation added to qligg_form_item_delete ajax action” and another is “Fix. current_user_can validation added to all ajax actions”. Looking at the changes made in that version we found before those changes anyone logged in to WordPress could delete the plugin’s feeds. Through cross-site request forgery (CSRF) an attacker could cause someone logged in to WordPress to delete them without intending it as well.


[Read more]