Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing insecure direct…
WPScan·CWE-283·Published 2021-08-09