Cross-Site Request Forgery in Custom Sidebars Plugin for WordPress
CVE-2017-18511

8.8HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
14 August 2019

Summary

The Custom Sidebars plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) vulnerabilities, which could allow unauthorized commands to be transmitted from a user that the website trusts. This issue affects versions before 3.0.8.1, making it essential for users to upgrade to the latest version to ensure their site remains secure. For more details, please refer to the official WordPress plugin page.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.