CVE-2014-9099

WhyDoWork AdSense <1.2 - CSRF

Title source: llm
STIX 2.1

Description

Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the whydowork_adsense page in wp-admin/options-general.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Dylan Irzi · textwebappsphp
https://www.exploit-db.com/exploits/39270

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68954

Scores

EPSS 0.0023
EPSS Percentile 45.2%

Details

CWE
CWE-352
Status published
Products (1)
whydowork_adsense_project/whydowork_adsense 1.2
Published Nov 26, 2014
Tracked Since Feb 18, 2026