Skip to main content
Loading…
    CVE-2023-5884 — The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to trick a logged in user to delete arbitrary avatars by — CVE Database · The Intelligence Room