关键信息 漏洞名称: WordPress Groovy Menu Plugin <= 1.4.3 is vulnerable to Cross Site Request Forgery (CSRF) 风险等级: Low priority 受影响版本: <= 1.4.3 修复情况: No official fix available 风险详情: - 类型: Cross Site Request Forgery (CSRF) - 描述: This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. 软件状态: This software is likely abandoned! Last updated over a year ago and will likely not receive further updates or fixes. 解决方案: - Remove and replace software. 详细信息: - Software: Groovy Menu - Type: Plugin - Vulnerable version: <= 1.4.3 - Fixed in: N/A 时间线: - Reported by Nguyen Xuan Chinh on 20 May 2022 - Early warning sent out to Patchstack customers on 26 Sep 2022