Security Advisory

CVE-2022-1709

4.3
MEDIUM

Vulnerability Description

The Throws SPAM Away WordPress plugin before 3.3.1 does not have CSRF checks in place when deleting comments (either all, spam, or pending), allowing attackers to make a logged in admin delete comments via a CSRF attack
Published Date June 8, 2022
Official Source NIST NVD Advisory