Featured Comments 1.2.1 - wp-admin/admin-ajax.php Comment Status Manipulation CSRF

Affects Plugin

fixed in version 1.2.5

References

CVE 2014-4163
CVE 2014-10382
PacketStorm 127023
SecurityFocus 67955
URL https://security.dxw.com/advisories/csrf-in-featured-comments-1-2-1-allows-an-attacker-to-set-and-unset-comment-statuses/

Classification

Type CSRF
CWE CWE-352

Miscellaneous

Views 6146
Verified No
WPVDB ID 7251

Timeline

Publicly Published 2014-08-01 (almost 6 years ago)
Added 2014-08-01 (almost 6 years ago)
Last Updated 2019-11-28 (8 months ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin