vendor:
User Role Editor
by:
Henry Hoggard
5.5
CVSS
MEDIUM
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: User Role Editor
Affected Version From: <=3.12
Affected Version To: 3.12
Patch Exists: YES
Related CWE:
CPE: a:wordpress:user_role_editor
Platforms Tested: Debian
2013
WP User Role Editor CSRF
This exploit allows an attacker to sign up with admin privileges by making the admin visit a CSRF script.
Mitigation:
Update to version 3.14 or higher