Cross-Site Request Forgery Vulnerabilities in Math Comment Spam Protection Plugin for WordPress
CVE-2008-0205
Currently unrated
Summary
Multiple cross-site request forgery (CSRF) vulnerabilities exist in math-comment-spam-protection.php within the Math Comment Spam Protection plugin for WordPress. These vulnerabilities enable remote attackers to perform unauthorized actions as administrators by leveraging the mcsp_opt_msg_no_answer or mcsp_opt_msg_wrong_answer parameters targeting wp-admin/options-general.php. This security flaw allows attackers to manipulate backend operations, posing a significant risk to site integrity and data security.
References
Timeline
Vulnerability published
Vulnerability Reserved