WP-Print <= 2.51 - Cross-Site Request Forgery

2013-04-05 00:00
Charlie Eriksen

Strategic Overview

Status
Patched in 2.52
Affected PluginWP-Print
Affected Version< 2.52
CVSS7.1High
CVECVE-2013-2693
View all WP-Print vulnerabilities

Vulnerability Overview

Cross-site request forgery (CSRF) vulnerability in the Options in the WP-Print plugin before 2.52 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unspecified vectors.

Technical Analysis

REMEDIATION: Update to version 2.52, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C