CVE-2023-29239
The LuckyWP Scripts Control plugin through version 1.2.1 contains a cross-site request forgery vulnerability stemming from inadequate nonce verification in the ItemController.php administrative file. An attacker could exploit this flaw by deceiving a site administrator into clicking a malicious link, allowing the attacker to perform unauthorized actions including adding, editing, deleting, enabling, disabling, and reordering items. The vulnerability affects all versions up to and including 1.2.1 and has been patched in version 1.2.2.
Based on public CVE data (MITRE/NVD).