Cross-Site Request Forgery Vulnerability in WP Comment Remix by WordPress
CVE-2008-4734

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
24 October 2008

Summary

The WP Comment Remix plugin before version 1.4.4 for WordPress contains a Cross-Site Request Forgery (CSRF) vulnerability. This flaw allows remote attackers to execute unauthorized commands on behalf of the site's administrators by crafting malicious requests. By exploiting the wpcr_hidden_form_input parameter, attackers may gain the ability to manipulate settings or perform actions without user consent, jeopardizing the integrity of the site.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.