The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset the Nokaut Offers Box WordPress plugin through 1.4.0 via a CSRF attack
| Software | From | Fixed in |
|---|---|---|
| nokautpl / nokaut_offers_box | - | 1.4.0.x |