AskApache Firefox Adsense <= 3.0 - Cross-Site Request Forgery
highCross-site request forgery (CSRF) vulnerability in askapache-firefox-adsense.php in the AskApache Firefox Adsense plugin 3.0 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the aafireadcode parameter to wp-...
- CVSS:
- 8.8
- Affected:
- up to 3.0
- Fix:
- No patched version reported
- Disclosed:
- Dec 26, 2013