Back to search
CVE-2015-4010
Published: Jun 9, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
Cross-site request forgery (CSRF) vulnerability in the Encrypted Contact Form plugin before 1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the iframe_url parameter in an Update Page action in the conformconf page to wp-admin/options-general.php.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
37264
exploit
x_refsource_EXPLOIT-DB
https://wpvulndb.com/vulnerabilities/7992
x_refsource_MISC
https://wordpress.org/plugins/encrypted-contact-form/changelog/
x_refsource_CONFIRM
73433
vdb-entry
x_refsource_BID
HPSBUX03281
vendor-advisory
x_refsource_HP
20150515 CSRF & XSS vulnerabilities in Encrypted Contact Form Wordpress Plugin v1.0.4
mailing-list
x_refsource_FULLDISC
20150606 CVE-2015-4010 - Cross-site Request Forgery & Cross-site Scripting in Encrypted Contact Form Wordpress Plugin v1.0.4
mailing-list
x_refsource_BUGTRAQ
https://plugins.trac.wordpress.org/changeset/1125443/
x_refsource_CONFIRM
SSRT101968
vendor-advisory
x_refsource_HP
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now