CVE-2014-10382: CSRF
Published Aug 22, 2019
·Updated
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
Affected Software
1 affected component
Pippinsplugins Featured Comments Wordpress<1.2.5
Event History
Aug 22, 2019
CVE Published
via MITRE·07:41 PM
Data Sourced
via MITRE·07:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-10382?
CVE-2014-10382 has a medium severity rating due to its potential to allow Cross-Site Request Forgery (CSRF) attacks.
2
How do I fix CVE-2014-10382?
To fix CVE-2014-10382, update the feature-comments plugin to version 1.2.5 or later.
3
What type of vulnerability is CVE-2014-10382?
CVE-2014-10382 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
Which versions of the feature-comments plugin are affected by CVE-2014-10382?
Versions of the feature-comments plugin prior to 1.2.5 are affected by CVE-2014-10382.
5
Is there a workaround for CVE-2014-10382 if I cannot update?
Currently, there is no known workaround for CVE-2014-10382; updating to the latest version is recommended.