ZeroHour

CVE-2019-17675

CVSS 3.1
8.8 high
EPSS
3%p86
Published
()
Modified
Description

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

Vendors
wordpressdebian
Products
wordpress, debian linux
Ecosystems
WordPress
Weakness
CWE-352, CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.