Cross-Site Request Forgery Vulnerability in WhyDoWork AdSense Plugin for WordPress
CVE-2014-9099
Currently unrated
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WhyDoWork AdSense plugin version 1.2 for WordPress. This flaw allows remote attackers to exploit administrator sessions by sending harmful requests to the admin panel. The attack is executed through an unauthorized request directed at the whydowork_adsense page within the wp-admin/options-general.php area, potentially leading to session hijacking and unauthorized actions being performed on behalf of the administrator.
References
Timeline
Vulnerability Reserved
Vulnerability published