Cross-Site Request Forgery Vulnerabilities in Contact Form Generator Plugin for WordPress
CVE-2015-6965

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
16 September 2015

What is CVE-2015-6965?

The Contact Form Generator plugin for WordPress contains multiple CSRF vulnerabilities that could allow remote attackers to exploit administrative permissions. By crafting malicious requests to the cfg_forms page within the wp-admin area, attackers can potentially hijack administrator sessions and perform unauthorized actions including creating, updating, or deleting form fields and templates. This vulnerability also opens avenues for cross-site scripting (XSS) attacks, further compromising site security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.