Cross-Site Request Forgery in GoDaddy Email Marketing Plugin for WordPress
CVE-2016-10903

8.8HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
21 August 2019

Summary

The GoDaddy Email Marketing Sign-Up Forms plugin for WordPress, prior to version 1.1.3, is susceptible to Cross-Site Request Forgery (CSRF). An attacker can exploit this vulnerability to perform actions on behalf of users without their consent, potentially compromising user data and the integrity of the application.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.