The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when deleting its shortcode, which could allow attackers to make logged in admins delete arbitrary shortcode via a CSRF attack
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Tiempo | Tiempo | * | 0.1.2 (including) |
References