Wordpress Alert: Cross-site request forgery against user management
An external page induces an authenticated administrator to change an account. Users or roles may be created, deleted, or changed.
What it looks like
An external page induces an authenticated administrator to change an account.
Why it matters
Users or roles may be created, deleted, or changed.
What to check
Audit user-management forms and requests for nonces and capabilities.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress nonces, WordPress roles and capabilities.
- Categories: WordPress
- Tags: #WordPress Security, #Cross-Site Scripting