Cross-Site Request Forgery in Disqus Comment System for WordPress
CVE-2014-5346

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
19 August 2014

Summary

The Disqus Comment System plugin version 2.77 for WordPress has multiple vulnerabilities that can be exploited via Cross-Site Request Forgery (CSRF) attacks. These vulnerabilities enable remote attackers to hijack the authentication of administrators. Through manipulation of requests, attackers can activate or deactivate the plugin, and they can also import or export comments without authentication. This poses significant risks, as unauthorized actions can lead to disruption of service and unauthorized comment management.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.