CVE-2016-10962: CSRF
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php optionname parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2016-10962.
What is the title of this vulnerability?
The title of this vulnerability is 'The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parame...'.
What is the severity of CVE-2016-10962?
The severity of CVE-2016-10962 is medium (6.5).
How can I fix the vulnerability in the icegram plugin for WordPress?
To fix the vulnerability in the icegram plugin for WordPress, update it to version 1.9.19 or newer.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_icegram_wordpress_plugin.html](https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_icegram_wordpress_plugin.html) and [https://wordpress.org/plugins/icegram/#developers](https://wordpress.org/plugins/icegram/#developers).