Description
The FL3R FeelBox WordPress plugin through 8.1 does not have CSRF check when updating reseting moods which could allow attackers to make logged in admins perform such action via a CSRF attack and delete the lydl_posts & lydl_poststimestamp DB tables
References
https://wpscan.com/vulnerability/483ed482-a1d1-44f6-8b99-56e653d3e45f
ExploitThird Party Advisory
https://wpscan.com/vulnerability/483ed482-a1d1-44f6-8b99-56e653d3e45f
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
4.3 · Medium
Information
Source identifier
Vulnerability status
Analyzed
Published
2023-01-30T20:15:11.197Z
3 years agoLast modified
2025-10-07T13:35:42.573Z
5 months ago