The Insights from Google PageSpeed WordPress plugin before 4.0.7 does not verify for CSRF before doing various actions such as deleting Custom URLs, which could allow attackers to make a logged in admin perform such actions via CSRF attacks
- https://wpscan.com/vulnerability/5c5955d7-24f0-45e6-9c27-78ef50446dad
- https://github.com/20142995/nuclei-templates