CVE-2014-4030
Currently unrated
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 25 June 2014
Summary
Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that remove players via a delete action to wp-admin/admin.php.
References
Timeline
Vulnerability published
Vulnerability Reserved