CVE-2015-10130: CSRF
The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the circlethumbnailsliderwithlightboximagemanagementfunc() function. This makes it possible for unauthenticated attackers to edit image data which can be used to inject malicious JavaScript, along with deleting images, and uploading malicious files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-10130?
CVE-2015-10130 has a medium severity due to the cross-site request forgery vulnerability.
How do I fix CVE-2015-10130?
To fix CVE-2015-10130, update the Team Circle Image Slider With Lightbox plugin to the latest version that includes nonce validation.
Who is affected by CVE-2015-10130?
Any WordPress user utilizing the Team Circle Image Slider With Lightbox plugin version 1.0 is affected by CVE-2015-10130.
What impact does CVE-2015-10130 have?
CVE-2015-10130 could allow attackers to perform unauthorized actions on behalf of users without their consent.
Is authentication required to exploit CVE-2015-10130?
No, exploitation of CVE-2015-10130 does not require authentication, making it a greater risk.