Back to search
CVE-2015-1874
Published: Mar 9, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
Cross-site request forgery (CSRF) vulnerability in the Contact Form DB (aka CFDB and contact-form-7-to-database-extension) plugin before 2.8.32 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete all plugin records via a request in the CF7DBPluginSubmissions page to wp-admin/admin.php.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
72964
vdb-entry
x_refsource_BID
20150304 CSRF in Contact Form DB allows attacker to delete all stored form submissions (WordPress plugin)
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now