#VU41060 Cross-site request forgery in WordPress - CVE-2014-9033
Published: November 26, 2014 / Updated: November 1, 2020
WordPress
WordPress.ORG
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.
Remediation
External links
- http://advisories.mageia.org/MGASA-2014-0493.html
- http://core.trac.wordpress.org/changeset/30418
- http://openwall.com/lists/oss-security/2014/11/25/12
- http://www.debian.org/security/2014/dsa-3085
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:233
- http://www.securitytracker.com/id/1031243
- https://wordpress.org/news/2014/11/wordpress-4-0-1/