Cross-Site Request Forgery Vulnerability in Contact Form DB Plugin for WordPress
CVE-2015-1874

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
9 March 2015

Summary

A cross-site request forgery (CSRF) vulnerability exists in the Contact Form DB plugin for WordPress, which allows remote attackers to hijack administrator authentication. This manipulation can lead to unauthorized requests that delete all records stored by the plugin. The vulnerability impacts versions prior to 2.8.32 and poses a significant risk if exploited, making it crucial for users to update their installations to protect against potential data loss.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.