Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:53
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/53125 - | |
References | () http://wordpress.org/plugins/wp-maintenance-mode/changelog/ - |
Information
Published : 2013-06-21 20:55
Updated : 2024-11-21 01:53
NVD link : CVE-2013-3250
Mitre link : CVE-2013-3250
CVE.ORG link : CVE-2013-3250
JSON object : View
Products Affected
wordpress
- wp_maintenance_mode_plugin
CWE
CWE-352
Cross-Site Request Forgery (CSRF)