Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and previous versions allows remote malicious users to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
wordpress wordpress |