CVE-2015-0895: CSRF
Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete logs of 404 (aka Not Found) HTTP status codes.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0895?
CVE-2015-0895 is considered to have a medium severity level due to the potential for remote attackers to exploit it.
How do I fix CVE-2015-0895?
To fix CVE-2015-0895, update the All In One WP Security & Firewall plugin to version 3.9.0 or later.
What types of attacks can be conducted due to CVE-2015-0895?
CVE-2015-0895 allows remote attackers to execute cross-site request forgery (CSRF) attacks, specifically targeting WordPress administrators.
Which plugin versions are affected by CVE-2015-0895?
CVE-2015-0895 affects All In One WP Security & Firewall plugin versions prior to 3.9.0.
What is the impact of CVE-2015-0895 on WordPress sites?
The impact of CVE-2015-0895 includes the potential hijacking of administrator authentication to delete important logs.