Cross-Site Request Forgery Vulnerability in Search Everything Plugin for WordPress
CVE-2014-3843

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
22 May 2014

Summary

The Search Everything plugin for WordPress suffers from a cross-site request forgery vulnerability that allows remote attackers to exploit the plugin for unauthorized actions, potentially leading to hijacking of user sessions. Attackers can manipulate victims’ sessions through crafted requests, increasing the risk of unauthorized access and data manipulation on affected WordPress sites.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.