FeedBurner FeedSmith <= 2.2 - Cross-Site Request Forgery
highCross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and hijack blog feeds via a request to wp-admin/options-general.php that submits parameter values to FeedBurner_FeedSmith_Plugin.php, as demonstrated by the (1) feedburner_url...
- CVSS:
- 8.8
- Affected:
- up to 2.2
- Fixed in:
- 2.3
- Disclosed:
- Oct 4, 2007