CVE-2013-6992: XSS
Cross-site request forgery (CSRF) vulnerability in askapache-firefox-adsense.php in the AskApache Firefox Adsense plugin 3.0 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the aafireadcode parameter to wp-admin/options-general.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6992?
CVE-2013-6992 is considered a high severity vulnerability due to its potential for exploitation through CSRF attacks.
How do I fix CVE-2013-6992?
To fix CVE-2013-6992, update the AskApache Firefox Adsense plugin to version 3.1 or higher.
What software is affected by CVE-2013-6992?
CVE-2013-6992 affects the AskApache Firefox Adsense plugin versions 3.0 and earlier.
What type of vulnerability is CVE-2013-6992?
CVE-2013-6992 is a cross-site request forgery (CSRF) vulnerability.
What can attackers do with CVE-2013-6992?
Attackers can exploit CVE-2013-6992 to hijack the authentication of WordPress administrators and execute cross-site scripting (XSS) attacks.