Cross-Site Request Forgery Vulnerability in WP Comment Remix by WordPress
CVE-2008-4734
Currently unrated
Summary
The WP Comment Remix plugin before version 1.4.4 for WordPress contains a Cross-Site Request Forgery (CSRF) vulnerability. This flaw allows remote attackers to execute unauthorized commands on behalf of the site's administrators by crafting malicious requests. By exploiting the wpcr_hidden_form_input parameter, attackers may gain the ability to manipulate settings or perform actions without user consent, jeopardizing the integrity of the site.
References
Timeline
Vulnerability published
Vulnerability Reserved