Описание
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.
| Релиз | Статус | Примечание | 
|---|---|---|
| artful | ignored  | end of life | 
| bionic | not-affected  | 4.6.1+dfsg-1 | 
| cosmic | not-affected  | 4.6.1+dfsg-1 | 
| devel | not-affected  | 4.6.1+dfsg-1 | 
| disco | not-affected  | 4.6.1+dfsg-1 | 
| eoan | not-affected  | 4.6.1+dfsg-1 | 
| esm-apps/bionic | not-affected  | 4.6.1+dfsg-1 | 
| esm-apps/focal | not-affected  | 4.6.1+dfsg-1 | 
| esm-apps/jammy | not-affected  | 4.6.1+dfsg-1 | 
| esm-apps/noble | not-affected  | 4.6.1+dfsg-1 | 
Показывать по
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_ ...
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.
EPSS
4.3 Medium
CVSS2
6.5 Medium
CVSS3