vendor:
Multisite Post Duplicator
by:
dxw
5,8
CVSS
MEDIUM
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: Multisite Post Duplicator
Affected Version From: 0.9.5.1
Affected Version To: 1.1.3
Patch Exists: YES
Related CWE: Awaiting assignment
CPE: a:wordpress:multisite_post_duplicator
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
Awaiting assignment
CSRF vulnerability in Multisite Post Duplicator
A CSRF vulnerability in Multisite Post Duplicator could allow an attacker to copy content from one site of a multisite installation to another. This could be used to add arbitrary HTML to the front-end of the site (which could be used for defacement, harvesting login credentials from authenticated users, or could be used to do virtually anything a logged-in admin user can do). This could also be used to view content not meant to be published.
Mitigation:
Update to version 1.1.3 or later.