ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Subscribe To Comments Reloaded Plugin <= 140204 - CSRF

Product
Subscribe To Comments Reloaded
Description
This plugin is prone to an options/index.php admin settings manipulation CSRF vulnerability. It allows to perform unauthorized actions in the context of a logged-in user of the affected application.
Solution
Update the plugin.
Classification
Type Cross Site Request Forgery (CSRF)
OWASP Top 10 A8: Cross Site Request Forgery (CSRF)
References
Security Focus
CVE
Name CVE-N/A
Versions
Affected In <= 140204
Fixed In 140219
Disclosure date
2014-08-01