Cross-Site Request Forgery Vulnerabilities in Contact Form Generator Plugin for WordPress
CVE-2015-6965

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
16 September 2015

Summary

The Contact Form Generator plugin for WordPress contains multiple CSRF vulnerabilities that could allow remote attackers to exploit administrative permissions. By crafting malicious requests to the cfg_forms page within the wp-admin area, attackers can potentially hijack administrator sessions and perform unauthorized actions including creating, updating, or deleting form fields and templates. This vulnerability also opens avenues for cross-site scripting (XSS) attacks, further compromising site security.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.