Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts Automatically plugin 0.7 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the lpa_post_letters parameter in the wp-limit-posts-automatically.php page to wp-admin/options-general.php.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-12-31 13:59
Updated : 2017-09-07 18:29
NVD link : CVE-2014-9401
Mitre link : CVE-2014-9401
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
wp_limit_posts_automatically_project
- wp_limit_posts_automatically