Brute Force Login Protection <= 1.5.1 - Cross-Site Request Forgery
highCross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module up to and including 1.5.1 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that have unknown impact via a crafted request to the brute-force-login-protection page to wp-admin/op...
- CVSS:
- 8.8
- Affected:
- up to 1.5.1
- Fix:
- No patched version reported
- Disclosed:
- May 17, 2015