PT-2015-4970 · WordPress · Banner Effect Header

Published

2015-01-08

·

Updated

2017-09-08

·

CVE-2015-0920

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Banner Effect Header plugin version 1.2.6
Description A cross-site request forgery (CSRF) issue allows remote attackers to hijack administrator authentication for requests that conduct cross-site scripting (XSS) attacks. This is achieved via the banner effect email parameter in the BannerEffectOptions page to "wp-admin/options-general.php".
Recommendations For Banner Effect Header plugin version 1.2.6, avoid using the banner effect email parameter in the BannerEffectOptions page until the issue is resolved. As a temporary workaround, consider restricting access to the BannerEffectOptions page to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-0920

Affected Products

Banner Effect Header