The Herd Effects WordPress plugin before 5.2.4 does not have CSRF when deleting its items, which could allow attackers to make logged in admins delete arbitrary effects via a CSRF attack
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Herd_effects | Wow-company | * | 5.2.4 (excluding) |
References