Cross-Site Request Forgery in Custom Sidebars Plugin for WordPress
CVE-2017-18511
8.8HIGH
Summary
The Custom Sidebars plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) vulnerabilities, which could allow unauthorized commands to be transmitted from a user that the website trusts. This issue affects versions before 3.0.8.1, making it essential for users to upgrade to the latest version to ensure their site remains secure. For more details, please refer to the official WordPress plugin page.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved