Cross-Site Request Forgery Vulnerability in WP Smiley Plugin for WordPress
CVE-2015-4140

Currently unrated

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
18 June 2015

Summary

The WP Smiley plugin version 1.4.1 for WordPress contains a cross-site request forgery (CSRF) vulnerability that allows remote attackers to hijack editor authentication. By manipulating requests sent through the smilies4wp.php page with the s4w-more parameter, attackers can execute cross-site scripting (XSS) payloads through wp-admin/options-general.php, compromising the integrity of user sessions and enabling potential malicious actions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.