Invite Anyone < 1.3.16 - Cross-Site Request Forgery

2017-03-22 00:00
Anonymous

Strategic Overview

Status
Patched in 1.3.16
Affected PluginInvite Anyone
Affected Version< 1.3.16
CVSS8.8High
CVECVE-2017-18544
View all Invite Anyone vulnerabilities

Vulnerability Overview

The Invite Anyone plugin before 1.3.16 for WordPress has admin-panel CSRF. The plugin’s setting pages had a vulnerability found in the nonce, which is used to prevent CSRF, but when the settings are saved there was no check to a validate if a nonce was included.

Technical Analysis

REMEDIATION: Update to version 1.3.16, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C