twitterDash [twitterdash] <= 2.1 (closed)
unknown
[en] Cross-site request forgery (CSRF) vulnerability in the twitterDash plugin 2.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the username_twitterDash parameter in the twitterDash.php page to wp-admin/...
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Dec 19, 2014
CVE-2014-9368 on NVD →
twitterDash <= 2.1 - Cross-Site Request Forgery to Cross-Site Scripting
high
The twitterDash plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing nonce validation on the twitterDash.php page. This makes it possible for unauthenticated attackers to inject malicious web scripts via the 'username_twitterDash' parameter throu...
- CVSS:
- 8.8
- Affected:
- up to 2.1
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2014
CVE-2014-9368 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database