Cross-Site Request Forgery Vulnerabilities in Math Comment Spam Protection Plugin for WordPress
CVE-2008-0205

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
10 January 2008

Summary

Multiple cross-site request forgery (CSRF) vulnerabilities exist in math-comment-spam-protection.php within the Math Comment Spam Protection plugin for WordPress. These vulnerabilities enable remote attackers to perform unauthorized actions as administrators by leveraging the mcsp_opt_msg_no_answer or mcsp_opt_msg_wrong_answer parameters targeting wp-admin/options-general.php. This security flaw allows attackers to manipulate backend operations, posing a significant risk to site integrity and data security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.