CVE-2014-4030
JW Player for Flash & HTML5 Video Plugin < 2.1.4 - Cross-Site Request Forgery via Player Deletion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-4030. PoCs published by Tom Adams.
AI-analyzed exploit summary This is a writeup describing a CSRF vulnerability in JW Player for Flash & HTML5 Video WordPress plugin. The provided URL demonstrates an unauthorized deletion action via a crafted request.
Description
Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that remove players via a delete action to wp-admin/admin.php.
Exploits (1)
This is a writeup describing a CSRF vulnerability in JW Player for Flash & HTML5 Video WordPress plugin. The provided URL demonstrates an unauthorized deletion action via a crafted request.