PT-2019-7353 · WordPress · Users-Ultra

Published

2019-09-20

·

Updated

2019-09-20

·

CVE-2015-9394

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions users-ultra plugin versions prior to 1.5.63 for WordPress
Description The issue concerns a CSRF vulnerability. It can be exploited via the action=package add new parameter to the "/wp-admin/admin-ajax.php" API endpoint.
Recommendations For versions prior to 1.5.63, update to version 1.5.63 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/wp-admin/admin-ajax.php" API endpoint to minimize the risk of exploitation. Avoid using the action parameter with the value package add new in the affected API endpoint until the issue is resolved.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-9394

Affected Products

Users-Ultra