Description
WordPress Plugin Flexi Quote Rotator is prone to a cross-site request forgery vulnerability and an SQL injection vulnerability. Attackers may exploit these issues to compromise the application, access or modify data, exploit vulnerabilities in the underlying database or to perform unauthorized actions by enticing a logged-in user to visit a malicious site. WordPress Plugin Flexi Quote Rotator version 0.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.9.3 or latest
References
Related Vulnerabilities
WordPress Plugin PDF & Print Button Joliprint Multiple Cross-Site Scripting Vulnerabilities (1.3.0)
Drupal Core 9.0.x Cross-Site Request Forgery (9.0.0 - 9.0.14)
Oracle JRE CVE-2012-0504 Vulnerability (CVE-2012-0504)
WordPress Plugin Improved user search in backend Cross-Site Request Forgery (1.2.4)
WordPress Plugin Ultimate Affiliate Pro Multiple Cross-Site Scripting Vulnerabilities (3.6)