Input validation vulnerability in WordPress 3.7

A type of attack called cross-site request forgery (CSRF) was discovered in versions of WordPress before 4.7.1. This type of attack allowed remote attackers to gain control of another person’s account without their knowledge. This was done by using a file that was uploaded with a Flash program.

Detected in:

WordPress fixed vulnerable versions: >= * < 3.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.