Description
WordPress Plugin MAZ Loader-Preloader Builder for WordPress is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin MAZ Loader-Preloader Builder for WordPress version 1.4.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.1 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:519205FF-2FF6-41E4-9E95-475AB2CE35B9
https://plugins.svn.wordpress.org/maz-loader/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Cross-Site Scripting (2.3.1)
SharePoint CVE-2021-31948 Vulnerability (CVE-2021-31948)
WordPress Plugin WP-Live Chat by 3CX Remote Code Execution (7.0.01)
MySQL CVE-2013-3783 Vulnerability (CVE-2013-3783)
Envoy Proxy Integer Overflow or Wraparound Vulnerability (CVE-2021-28682)