ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Pods Plugin <= 2.4 - Multiple CSRF

Product
Pods
Description
Because of these vulnerabilities, the attackers can hijack the authentication of administrators for requests that conduct cross-site scripting attacks via the "toggled" parameter in the pods-components page to wp-admin/admin.php, reset pod settings and data via the "pods_reset" parameter in the pod-settings page to wp-admin/admin.php, delete the admin role via the "id" parameter in the pods-component-roles-and-capabilities page to wp-admin/admin.php, delete a pod in a delete action in the pods page to wp-admin/admin.php, enable "roles and capabilities" in the pods-components page to wp-admin/admin.php or deactivate and reset pod data via the "pods_reset_deactivate" parameter in the pod-settings page to wp-admin/admin.php.
Solution
Update the plugin.
Classification
Type Multi
References
CVE Mitre
CVE
Name CVE-2014-7957
Versions
Affected In <= 2.4
Fixed In 2.5
Disclosure date
2014-10-07
Credits
Pietro Oliva