CVE-2018-1000507

WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types. This attack appear to be exploitable via Admin must click on link. This vulnerability appears to have been fixed in 2.1.1.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:jjj:wp_user_groups:2.0.0:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 03:40

Type Values Removed Values Added
References () https://advisories.dxw.com/advisories/csrf-wp-user-groups/ - Exploit, Third Party Advisory () https://advisories.dxw.com/advisories/csrf-wp-user-groups/ - Exploit, Third Party Advisory

Information

Published : 2018-06-26 16:29

Updated : 2024-11-21 03:40


NVD link : CVE-2018-1000507

Mitre link : CVE-2018-1000507

CVE.ORG link : CVE-2018-1000507


JSON object : View

Products Affected

jjj

  • wp_user_groups
CWE
CWE-352

Cross-Site Request Forgery (CSRF)