HPSBUX03281Vendor advisory
http://marc.info/?l=bugtraq&m=142607790919348&w=2 CVE-2015-4010
WordPress Plugin Encrypted Contact Form 1.0.4 - Cross-Site Request Forgery
Record summary
CVE-2015-4010 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Cross-site request forgery (CSRF) vulnerability in the Encrypted Contact Form plugin before 1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the iframe_url parameter in an Update Page action in the conformconf page to wp-admin/options-general.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Encrypted Contact Form 1.0.4 - Cross-Site Request ForgeryExploitDB exploitby Nitin VenkateshNot analyzed1 file
References
10packetstormsecurity.com
http://packetstormsecurity.com/files/132209/WordPress-Encrypted-Contact-Form-1.0.4-CSRF-XSS.html 20150515 CSRF & XSS vulnerabilities in Encrypted Contact Form Wordpress Plugin v1.0.4mailing list
http://seclists.org/fulldisclosure/2015/May/63 20150606 CVE-2015-4010 - Cross-site Request Forgery & Cross-site Scripting in Encrypted Contact Form Wordpress Plugin v1.0.4mailing list
http://www.securityfocus.com/archive/1/535699/100/0/threaded 73433vdb entry
http://www.securityfocus.com/bid/73433 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-4010 plugins.trac.wordpress.orgConfirmation
https://plugins.trac.wordpress.org/changeset/1125443 wordpress.orgConfirmation
https://wordpress.org/plugins/encrypted-contact-form/changelog wpvulndb.com
https://wpvulndb.com/vulnerabilities/7992 37264exploit
https://www.exploit-db.com/exploits/37264