8.8

CVE-2012-10015

BestWebSoft Twitter Plugin Settings Page twitter.php twttr_settings_page cross-site request forgery

BestWebSoft's Twitter <= 2.14 - Cross-Site Request Forgery

A vulnerability was found in BestWebSoft Twitter Plugin up to 2.14 on WordPress. It has been classified as problematic. Affected is the function twttr_settings_page of the file twitter.php of the component Settings Page. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. Upgrading to version 2.15 is able to address this issue. The patch is identified as a6d4659cbb2cbf18ccb0fb43549d5113d74e0146. It is recommended to upgrade the affected component. VDB-230154 is the identifier assigned to this vulnerability.
Mögliche Gegenmaßnahme
BestWebSoft's Twitter: Update to version 2.15, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BestwebsoftTwitter SwPlatformwordpress Version < 2.15
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt BestWebSoft's Twitter
Version *-2.14
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.344
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cna@vuldb.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cna@vuldb.com 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

https://github.com/wp-plugins/twitter-plugin/commit/a6d4659cbb2cbf18ccb0fb43549d5113d74e0146
Patch
https://vuldb.com/?ctiid.230154
Third Party Advisory
Permissions Required
https://vuldb.com/?id.230154
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/d6198e3e-a8e8-4d67-a0d6-b62f187d4903
Third Party Advisory