CVE-2015-4089
WP Fastest Cache < 0.8.3.5 - Multiple Cross-Site Request Forgery
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before 0.8.3.5 for WordPress allow remote attackers to hijack the authentication of unspecified victims for requests that call the (1) saveOption, (2) deleteCache, (3) deleteCssAndJsCache, or (4) addCacheTimeout method via the wpFastestCachePage parameter in the WpFastestCacheOptions/ page.
Múltiples vulnerabilidades de tipo Cross-Site Request Forgery (CSRF) en la función optionsPageRequest en admin.php en el plugin WP Fastest Cache en versiones anteriores a la 0.8.3.5 para WordPress permiten que los atacantes remotos secuestren la autenticación de víctimas sin especificar para peticiones que llamen a los métodos (1) saveOption, (2) deleteCache, (3) deleteCssAndJsCache, o (4) addCacheTimeout mediante el parámetro wpFastestCachePage en la página WpFastestCacheOptions/ page.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-05-26 CVE Reserved
- 2015-05-26 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2015/05/26/20 | Mailing List | |
https://wordpress.org/plugins/wp-fastest-cache/#developers | Third Party Advisory | |
https://wpvulndb.com/vulnerabilities/9756 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wpfastestcache Search vendor "Wpfastestcache" | Wp Fastest Cache Search vendor "Wpfastestcache" for product "Wp Fastest Cache" | <= 0.8.3.4 Search vendor "Wpfastestcache" for product "Wp Fastest Cache" and version " <= 0.8.3.4" | wordpress |
Affected
|