Mail On Update < 5.3.0 - Cross-Site Request Forgery

2013-05-16 00:00
Henri Salo (fgeek)

Strategic Overview

Status
Patched in 5.3.0
Affected PluginMail On Update
Affected Version< 5.3.0
CVSS8.8High
CVECVE-2013-2107
View all Mail On Update vulnerabilities

Vulnerability Overview

Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change the "List of alternative recipients" via the mailonupdate_mailto parameter in the mail-on-update page to wp-admin/options-general.php. NOTE: a third party claims that 5.2.1 and 5.2.2 are also vulnerable, but the issue might require a separate CVE identifier since this might reflect an incomplete fix.

Technical Analysis

REMEDIATION: Update to version 5.3.0, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C