Loginizer <= 1.3.5 - Cross-Site Request Forgery

2017-08-08 00:00
Jonas Lejon

Strategic Overview

Status
Patched in 1.3.6
Affected PluginLoginizer
Affected Version< 1.3.6
CVSS8.8High
CVECVE-2017-12651
View all Loginizer vulnerabilities

Vulnerability Overview

Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.

Technical Analysis

REMEDIATION: Update to version 1.3.6, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C