Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before 0.8.3.5 for WordPress allow remote attackers to hijack the authentication of unspecified victims for requests that call the (1) saveOption, (2) deleteCache, (3) deleteCssAndJsCache, or (4) addCacheTimeout method via the wpFastestCachePage parameter in the WpFastestCacheOptions/ page.
References
Link | Resource |
---|---|
https://wordpress.org/plugins/wp-fastest-cache/#developers | Third Party Advisory |
http://www.openwall.com/lists/oss-security/2015/05/26/20 | Mailing List Third Party Advisory |
https://wpvulndb.com/vulnerabilities/9756 |
Configurations
Information
Published : 2017-09-19 08:29
Updated : 2019-08-31 23:15
NVD link : CVE-2015-4089
Mitre link : CVE-2015-4089
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
wpfastestcache
- wp_fastest_cache