WordPress versions released before 5.2.4 do not check if the person visiting the admin pages is who they say they are. This could potentially lead to a type of cyber attack known as Cross-Site Request Forgery (CSRF).
Documentation: Home / Vulnerabilities / Access violation vulnerability in WordPress 3.7
WordPress versions released before 5.2.4 do not check if the person visiting the admin pages is who they say they are. This could potentially lead to a type of cyber attack known as Cross-Site Request Forgery (CSRF).
This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!
Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:
> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21
Is this information incorrect? Please leave us a message.
© Really Simple Plugins
CoC 70461155
Kalmarweg 14-5
9723 JG, Groningen (NL)