From d1427d5f99ca8b29a7b6f0d02ed4bf6d7cc4a952 Mon Sep 17 00:00:00 2001 From: ethicalhack3r Date: Thu, 26 Jun 2014 22:04:53 +0200 Subject: [PATCH] Add url to featured-comments plugin --- data/plugin_vulns.xml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/data/plugin_vulns.xml b/data/plugin_vulns.xml index 7971b26e..a29b7f7f 100644 --- a/data/plugin_vulns.xml +++ b/data/plugin_vulns.xml @@ -12984,10 +12984,11 @@ - Featured Comments 1.2.1 -wp-admin/admin-ajax.php Comment Status Manipulation CSRF + Featured Comments 1.2.1 - wp-admin/admin-ajax.php Comment Status Manipulation CSRF 107844 2014-4163 + https://security.dxw.com/advisories/csrf-in-featured-comments-1-2-1-allows-an-attacker-to-set-and-unset-comment-statuses/ http://www.securityfocus.com/bid/67955 http://packetstormsecurity.com/files/127023/