PT-2007-2665 · WordPress · Wordpress
G30Rg3_X
·
Published
2007-03-03
·
Updated
2018-10-16
·
CVE-2007-1244
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WordPress versions prior to 2.1.1
Description
A cross-site request forgery (CSRF) issue exists in the AdminPanel, allowing remote attackers to perform actions with administrator privileges. This can be exploited using the delete action in "wp-admin/post.php". Additionally, this issue can be used to conduct cross-site scripting (XSS) attacks and steal cookies via the
post parameter.Recommendations
For WordPress versions prior to 2.1.1, update to a version that addresses this issue to prevent exploitation. As a temporary workaround, consider restricting access to the AdminPanel and the "wp-admin/post.php" endpoint to minimize the risk of exploitation. Avoid using the
post parameter in sensitive operations until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wordpress