Cross-site request forgery (CSRF) vulnerability in the Member Approval plugin 131109 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings to their default and disable registration approval via a request to wp-admin/options-general.php.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-06-11 07:55
Updated : 2014-06-12 09:10
NVD link : CVE-2014-3850
Mitre link : CVE-2014-3850
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
member_approval_plugin_project
- member_approval