WordPress DX-Contribute Plugin Cross Site Request Forgery Vulnerability
3 Dec. 2012
Summary
The DX-Contribute plugin for WordPress is prone to a cross-site request-forgery vulnerability because the application fails to properly validate HTTP requests.
Credit:
The information has been provided by Zhao Liang.
DX-Contribute plugin for WordPress is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading an authenticated user to visit a malicious Web site, a remote attacker could send a malformed HTTP request to perform cross-site request forgery attacks. An attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities.