CVE-2015-0895

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
7 March 2015

Summary

Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete logs of 404 (aka Not Found) HTTP status codes.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.