ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Cool Video Gallery Plugin <= 1.8 - CSRF

Product
Cool Video Gallery
Description
Cross site request forgery vulnerability is in the details.php, admin/gallery-manage.php Gallery Deletion, admin/gallery-settings.php Gallery Settings Manipulation, admin/gallery-sort.php Gallery Sort Order Manipulation, admin/player-settings.php Player Settings Manipulation, admin/plugin-uninstall.php Plugin Uninstallation, admin/video-sitemap.php XML Video Sitemap Generation, lib/core.php .
Solution
Update the plugin.
Classification
Type Cross Site Request Forgery (CSRF)
OWASP Top 10 A8: Cross Site Request Forgery (CSRF)
References
CVE
Name CVE-N/A
Versions
Affected In <= 1.8
Fixed In 1.9
Disclosure date
2014-08-01