NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
46571  CVE-2012-5387  Cross-site request forgery (CSRF) vulnerability in wlcms-plugin.php in the White Label CMS plugin before 1.5.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify the developer name via the wlcms_o_developer_name parameter in a save action to wp-admin/admin.php, as demonstrated by a developer name containing XSS sequences.    6.8  Medium  2017-01-19  2013-08-19  View
7127  CVE-2017-5489  Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims via vectors involving a Flash file upload.    6.8  Medium  2017-07-18  2017-07-17  View
11486  CVE-2011-5226  Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to hijack the authentication of an administrator for requests that trigger snapshots.    6.8  Medium  2017-01-07  2012-10-26  View
45833  CVE-2012-4448  Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.    6.8  Medium  2017-01-19  2012-10-01  View
26803  CVE-2015-5731  Cross-site request forgery (CSRF) vulnerability in wp-admin/post.php in WordPress before 4.2.4 allows remote attackers to hijack the authentication of administrators for requests that lock a post, and consequently cause a denial of service (editing blockage), via a get-post-lock action.    6.8  Medium  2017-01-19  2016-12-07  View

Page 2903 of 17672, showing 5 records out of 88360 total, starting on record 14511, ending on 14515

Actions