Description
WordPress Plugin WP-FB-AutoConnect is prone to multiple cross-site request forgery vulnerabilities. Exploiting these issues may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin WP-FB-AutoConnect version 4.0.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.0.6 or latest
References
Related Vulnerabilities
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-40601)
PHP Improper Input Validation Vulnerability (CVE-2016-4072)
Oracle HTTP Server CVE-2007-0280 Vulnerability (CVE-2007-0280)
WordPress Plugin Yasr-Yet Another Stars Rating SQL Injection (0.9.0)
WordPress Plugin Import all XML, CSV & TXT into WordPress Arbitrary File Disclosure (3.7)