CVE-2014-5347

Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) disqus_replace, (2) disqus_public_key, or (3) disqus_secret_key parameter to wp-admin/edit-comments.php in manage.php or that (4) reset or (5) delete plugin options via the reset parameter to wp-admin/edit-comments.php.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
disqusdisqus_comment_system
𝑥
≤ 2.75
disqusdisqus_comment_system
2.40
disqusdisqus_comment_system
2.41
disqusdisqus_comment_system
2.42
disqusdisqus_comment_system
2.43
disqusdisqus_comment_system
2.44
disqusdisqus_comment_system
2.45
disqusdisqus_comment_system
2.46
disqusdisqus_comment_system
2.47
disqusdisqus_comment_system
2.48
disqusdisqus_comment_system
2.49
disqusdisqus_comment_system
2.50
disqusdisqus_comment_system
2.51
disqusdisqus_comment_system
2.52
disqusdisqus_comment_system
2.53
disqusdisqus_comment_system
2.54
disqusdisqus_comment_system
2.55
disqusdisqus_comment_system
2.60
disqusdisqus_comment_system
2.61
disqusdisqus_comment_system
2.62
disqusdisqus_comment_system
2.63
disqusdisqus_comment_system
2.64
disqusdisqus_comment_system
2.65
disqusdisqus_comment_system
2.66
disqusdisqus_comment_system
2.67
disqusdisqus_comment_system
2.68
disqusdisqus_comment_system
2.69
disqusdisqus_comment_system
2.70
disqusdisqus_comment_system
2.71
disqusdisqus_comment_system
2.72
disqusdisqus_comment_system
2.73
disqusdisqus_comment_system
2.74
𝑥
= Vulnerable software versions