ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Improved User Search in Backend Plugin <= 1.2.4 - CSRF

Product
Improved User Search in Backend
Description
Because of this vulnerability in improved-user-search-in-backend.php, the attackers can hijack the authentication of administrators for requests that insert XSS sequences.
Solution
Update the plugin.
Classification
Type Cross Site Request Forgery (CSRF)
OWASP Top 10 A8: Cross Site Request Forgery (CSRF)
References
CVE Mitre
CVE
Name CVE-2014-5196
Versions
Affected In <= 1.2.4
Fixed In 1.2.5
Disclosure date
2014-08-12