PT-2014-8984 · Twitter · Post To Twitter Plugin

Published

2014-12-31

·

Updated

2017-09-08

·

CVE-2014-9393

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Post to Twitter plugin versions 0.7 and earlier
Description The issue allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks. This is achieved via the idptt twitter username or idptt tweet prefix parameter to "wp-admin/options-general.php".
Recommendations For Post to Twitter plugin versions 0.7 and earlier, consider disabling the plugin until a patch is available to prevent potential cross-site request forgery (CSRF) attacks. Restrict access to the "wp-admin/options-general.php" endpoint to minimize the risk of exploitation. Avoid using the idptt twitter username and idptt tweet prefix parameters in the affected endpoint until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9393

Affected Products

Post To Twitter Plugin