CVE-2014-2559

Twitget <3.3.3 - CSRF

Title source: llm

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that change unspecified plugin options via a request to wp-admin/options-general.php.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/32868

Scores

EPSS 0.0109
EPSS Percentile 78.0%

Details

CWE
CWE-352
Status published
Products (1)
twitget_project/twitget < 3.3.1
Published Oct 17, 2014
Tracked Since Feb 18, 2026