CVE-2012-4921
Multiple cross-site request forgery (CSRF) vulnerabilities in the DVS Custom Notification plugin 1.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change application settings or…
Does this matter?
Lower severity and a low EPSS score (0.96%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site request forgery (CSRF) vulnerabilities in the DVS Custom Notification plugin 1.0.1 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change application settings or (2) conduct cross-site scripting (XSS) attacks.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.96% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- dvs custom notification project/dvs custom notification
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://osvdb.org/89441
- http://secunia.com/advisories/51531Vendor Advisory
- http://osvdb.org/89441
- http://secunia.com/advisories/51531Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.