vendor:
Simple Add Pages or Posts
by:
ALIREZA_PROMIS
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Simple Add Pages or Posts
Affected Version From: 1.6
Affected Version To: 1.6
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:simple_add_pages_or_posts:1.6
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu/FireFox
2016
WordPress simple add pages or posts CSRF Vulnerability
A CSRF vulnerability exists in the Wordpress plugin 'Simple Add Pages or Posts' version 1.6, which allows an attacker to add pages or posts to a Wordpress site. An attacker can craft a malicious HTML form and send it to a victim, who is logged into the Wordpress site. When the victim submits the form, the attacker can add pages or posts to the Wordpress site. The HTML code and live POST request are provided in the text.
Mitigation:
The plugin should be updated to the latest version, and the user should be aware of malicious HTML forms.