CVE-2014-9099

WhyDoWork AdSense 1.2 - Cross-Site Request Forgery via wp-admin/options-general.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-9099. PoCs published by Dylan Irzi.

AI-analyzed exploit summary This is a writeup describing a cross-site scripting (XSS) and cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin for WordPress. It includes a sample HTTP POST request demonstrating the vulnerability but does not contain executable exploit code.

Description

Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the whydowork_adsense page in wp-admin/options-general.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Dylan Irzi · textwebappsphp
https://www.exploit-db.com/exploits/39270

This is a writeup describing a cross-site scripting (XSS) and cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin for WordPress. It includes a sample HTTP POST request demonstrating the vulnerability but does not contain executable exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: WhyDoWork AdSense plugin for WordPress 1.2 and prior
Auth required
Prerequisites: Authenticated access to WordPress admin panel
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68954

Scores

EPSS 0.0269
EPSS Percentile 84.0%

Details

CWE
CWE-352
Status published
Products (1)
whydowork_adsense_project/whydowork_adsense 1.2
Published Nov 26, 2014
Tracked Since Feb 18, 2026