Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-18853
HistoryMar 02, 2022 - 12:00 a.m.

WordPress Support Board plugin跨站请求伪造漏洞

2022-03-0200:00:00
China National Vulnerability Database
www.cnvd.org.cn
15
wordpress
support board plugin
cross-site request forgery
csrf
vulnerability
php
mysql
ajax file
administrator users

EPSS

0.001

Percentile

33.4%

WordPress is the Wordpress Foundation’s suite of blogging platforms developed using the PHP language. The platform supports personal blogging sites on servers with PHP and MySQL. cross-site request forgery vulnerability exists in versions of the WordPress Support Board plugin prior to 3.3.6, which stems from the plugin not having any CSRF checking operations handled by the included ajax.php file. An attacker could exploit this vulnerability to administrator users.

EPSS

0.001

Percentile

33.4%