Cross-Site Request Forgery Vulnerability in White Label CMS Plugin for WordPress
CVE-2012-5387
Currently unrated
What is CVE-2012-5387?
A cross-site request forgery (CSRF) vulnerability exists in the wlcms-plugin.php file of the White Label CMS plugin for WordPress prior to version 1.5.1. This flaw can be exploited by remote attackers who can hijack the authentication of administrators. By sending a specially crafted request, attackers can modify the developer name using the āwlcms_o_developer_nameā parameter during a save action to wp-admin/admin.php. This attack can inject XSS sequences, potentially compromising the security of the WordPress installation.