Cross-Site Request Forgery Vulnerability in WP Smiley Plugin for WordPress
CVE-2015-4140
Currently unrated
Summary
The WP Smiley plugin version 1.4.1 for WordPress contains a cross-site request forgery (CSRF) vulnerability that allows remote attackers to hijack editor authentication. By manipulating requests sent through the smilies4wp.php page with the s4w-more parameter, attackers can execute cross-site scripting (XSS) payloads through wp-admin/options-general.php, compromising the integrity of user sessions and enabling potential malicious actions.
References
Timeline
Vulnerability published
Vulnerability Reserved