Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts Automatically plugin 0.7 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the lpa_post_letters parameter in the wp-limit-posts-automatically.php page to wp-admin/options-general.php.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2014-12-31T21:00:00

Updated: 2017-09-07T15:57:01

Reserved: 2014-12-17T00:00:00


Link: CVE-2014-9401

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2014-12-31T21:59:14.077

Modified: 2017-09-08T01:29:34.137


Link: CVE-2014-9401

JSON object: View

cve-icon Redhat Information

No data.

CWE