CVE-2015-9498: CSRF
Published Oct 22, 2019
·Updated
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
Affected Software
1 affected component
Wpserveur Wps Hide Login Wordpress<1.1
Event History
Oct 22, 2019
CVE Published
via MITRE·08:36 PM
Data Sourced
via MITRE·08:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9498?
CVE-2015-9498 is considered a medium severity vulnerability due to its impact on the integrity of option values.
2
What type of vulnerability is CVE-2015-9498?
CVE-2015-9498 is a Cross-Site Request Forgery (CSRF) vulnerability.
3
How do I fix CVE-2015-9498?
To fix CVE-2015-9498, upgrade the WPS Hide Login plugin to version 1.1 or later.
4
What versions of WPS Hide Login are affected by CVE-2015-9498?
WPS Hide Login versions before 1.1 are affected by CVE-2015-9498.
5
What can attackers do exploit CVE-2015-9498?
Attackers can exploit CVE-2015-9498 to change option values without proper authorization.