The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.
References
Link | Resource |
---|---|
https://www.pluginvulnerabilities.com/2019/07/29/vulnerability-details-cross-site-request-forgery-csrf-cross-site-scripting-xss-in-animate-it/ | Third Party Advisory |
https://wordpress.org/plugins/animate-it/#developers | Product Release Notes |
https://plugins.trac.wordpress.org/changeset?old_path=%2Fanimate-it%2Ftags%2F2.3.6%2Fedsanimate.php&old=2129363&new_path=%2Fanimate-it%2Ftags%2F2.3.5%2Fedsanimate.php | Patch Third Party Advisory |
https://wpvulndb.com/vulnerabilities/9900 | Third Party Advisory |
Configurations
Information
Published : 2019-10-10 14:15
Updated : 2019-10-15 07:22
NVD link : CVE-2019-17386
Mitre link : CVE-2019-17386
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
eleopard
- animate_it\!