PT-2007-2665 · WordPress · Wordpress

G30Rg3_X

·

Published

2007-03-03

·

Updated

2018-10-16

·

CVE-2007-1244

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 2.1.1
Description A cross-site request forgery (CSRF) issue exists in the AdminPanel, allowing remote attackers to perform actions with administrator privileges. This can be exploited using the delete action in "wp-admin/post.php". Additionally, this issue can be used to conduct cross-site scripting (XSS) attacks and steal cookies via the post parameter.
Recommendations For WordPress versions prior to 2.1.1, update to a version that addresses this issue to prevent exploitation. As a temporary workaround, consider restricting access to the AdminPanel and the "wp-admin/post.php" endpoint to minimize the risk of exploitation. Avoid using the post parameter in sensitive operations until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1244

Affected Products

Wordpress