vendor:
Global Content Blocks WordPress Plugin
by:
Summer of Pwnage
7,5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Global Content Blocks WordPress Plugin
Affected Version From: 2.1.5
Affected Version To: 2.1.5
Patch Exists: NO
Related CWE: N/A
CPE: a:global_content_blocks:global_content_blocks
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2016
Cross-Site Request Forgery in Global Content Blocks WordPress Plugin
The Global Content Blocks WordPress Plugin is vulnerable to Cross-Site Request Forgery. Amongst others, this issue can be used to update a content block to overwrite it with arbitrary PHP code. Visiting a page or blog post that uses this content block will cause the attacker's PHP code to be executed.
Mitigation:
There is currently no fix available.