CVE-2013-3252
NONE EPSS 61.5%
Published Apr 10, 201412y ago · Modified Jun 16, 20262w ago
Published Apr 10, 2014 12y ago
Last Modified Jun 16, 2026 2w ago
Description
Cross-site request forgery (CSRF) vulnerability in the options admin page in the WP-PostViews plugin before 1.63 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.
Threat Intelligence
EPSS Exploit Probability
61.5% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-352 Cross-Site Request Forgery (CSRF) Authentication
Affected Products 13
| Vendor | Product | Version | Range |
|---|---|---|---|
| lesterchan | wp-postviews | * | ≤1.62 |
| lesterchan | wp-postviews | 1.00 | any |
| lesterchan | wp-postviews | 1.01 | any |
| lesterchan | wp-postviews | 1.02 | any |
| lesterchan | wp-postviews | 1.10 | any |
| lesterchan | wp-postviews | 1.11 | any |
| lesterchan | wp-postviews | 1.20 | any |
| lesterchan | wp-postviews | 1.30 | any |
| lesterchan | wp-postviews | 1.31 | any |
| lesterchan | wp-postviews | 1.40 | any |
| lesterchan | wp-postviews | 1.50 | any |
| lesterchan | wp-postviews | 1.60 | any |
| lesterchan | wp-postviews | 1.61 | any |
References 3
- osvdb.org http://osvdb.org/93096
- secunia.com http://secunia.com/advisories/53127
- wordpress.org http://wordpress.org/plugins/wp-postviews/changelog
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.