Multiple cross-site request forgery (CSRF) vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin before 1.5.7, 1.6.x before 1.6.4, and 1.7.x before 1.7.4 for WordPress allow remote attackers to hijack the authentication of certain users for requests that conduct SQL injection attacks via the (1) order_by or (2) order parameter in the wpseo_bulk-editor page.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2015-03-17T15:00:00

Updated: 2015-03-17T14:57:00

Reserved: 2015-03-14T00:00:00


Link: CVE-2015-2293

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2015-03-17T15:59:01.847

Modified: 2015-03-18T16:13:37.877


Link: CVE-2015-2293

JSON object: View

cve-icon Redhat Information

No data.

CWE