Report
The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Score:5.4
Severity:Medium
Version: 1.1
The plugin vendor has not patched this vulnerability at the moment.