Cross-Site Request Forgery Vulnerabilities in Contact Form Generator Plugin for WordPress
CVE-2015-6965
Currently unrated
What is CVE-2015-6965?
The Contact Form Generator plugin for WordPress contains multiple CSRF vulnerabilities that could allow remote attackers to exploit administrative permissions. By crafting malicious requests to the cfg_forms page within the wp-admin area, attackers can potentially hijack administrator sessions and perform unauthorized actions including creating, updating, or deleting form fields and templates. This vulnerability also opens avenues for cross-site scripting (XSS) attacks, further compromising site security.