Multiple cross-site request forgery (CSRF) vulnerabilities in the Post to Twitter plugin 0.7 and previous versions for WordPress allow remote malicious users to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) idptt_twitter_username or (2) idptt_tweet_prefix parameter to wp-admin/options-general.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
post to twitter project post to twitter |