CVE-2014-5199
WordPress File Upload < 2.4.2 - Cross-Site Request Forgery
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors. NOTE: some of these details are obtained from third party information.
Vulnerabilidad de CSRF en el plugin WordPress File Upload (wp-file-upload) anterior a 2.4.2 para WordPress permite a atacantes remotos secuestrar la autenticación de administradores para solicitudes que cambian las configuraciones de plugins a través de vectores no especificados. NOTA: algunos de estos detalles se obtienen de información de terceras partes.
Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-08-08 CVE Published
- 2014-08-12 CVE Reserved
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/60520 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://wordpress.org/plugins/wp-file-upload/changelog | 2014-08-13 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress File Upload Project Search vendor "Wordpress File Upload Project" | Wordpress File Upload Search vendor "Wordpress File Upload Project" for product "Wordpress File Upload" | <= 2.4.1 Search vendor "Wordpress File Upload Project" for product "Wordpress File Upload" and version " <= 2.4.1" | wordpress |
Affected
|