PT-2019-13777 · WordPress · Deny All Firewall

Published

2019-08-08

·

Updated

2019-08-20

·

CVE-2019-14681

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Deny All Firewall plugin versions prior to 1.1.7
Description The issue allows for a CSRF attack via the wp-admin/options-general.php?page=daf settings&daf remove=true endpoint, potentially affecting the security of WordPress installations using the Deny All Firewall plugin.
Recommendations For Deny All Firewall plugin versions prior to 1.1.7, update to version 1.1.7 or later to resolve the issue.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14681

Affected Products

Deny All Firewall