CVE-2014-6312
15.10.2014, 14:55
Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before 3.2.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the custom_style_afo parameter on the login_widget_afo page to wp-admin/options-general.php.
Vendor | Product | Version |
---|---|---|
login_widget_with_shortcode_project | login_widget_with_shortcode | 𝑥 ≤ 3.1.1 |
login_widget_with_shortcode_project | login_widget_with_shortcode | 1.0.1 |
login_widget_with_shortcode_project | login_widget_with_shortcode | 2.0.1 |
login_widget_with_shortcode_project | login_widget_with_shortcode | 2.0.2 |
login_widget_with_shortcode_project | login_widget_with_shortcode | 2.1.3 |
login_widget_with_shortcode_project | login_widget_with_shortcode | 2.2.3 |
login_widget_with_shortcode_project | login_widget_with_shortcode | 2.2.4 |
𝑥
= Vulnerable software versions
References