ZeroHour

CVE-2017-12651

CVSS 3.0
8.8 high
EPSS
<1%p52
Published
()
Modified
Description

Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.

Vendors
loginizer
Products
loginizer
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.