PT-2015-4970 · WordPress · Banner Effect Header
Published
2015-01-08
·
Updated
2017-09-08
·
CVE-2015-0920
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Banner Effect Header plugin version 1.2.6
Description
A cross-site request forgery (CSRF) issue allows remote attackers to hijack administrator authentication for requests that conduct cross-site scripting (XSS) attacks. This is achieved via the
banner effect email parameter in the BannerEffectOptions page to "wp-admin/options-general.php".Recommendations
For Banner Effect Header plugin version 1.2.6, avoid using the
banner effect email parameter in the BannerEffectOptions page until the issue is resolved. As a temporary workaround, consider restricting access to the BannerEffectOptions page to minimize the risk of exploitation.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Banner Effect Header