CVE-2017-5492: CSRF
Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote attackers to hijack the authentication of unspecified victims for requests that perform a widgets-access action, related to wp-admin/includes/class-wp-screen.php and wp-admin/widgets.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5492?
CVE-2017-5492 has a medium severity due to its ability to allow unauthorized actions on behalf of authenticated users.
How do I fix CVE-2017-5492?
The recommended fix for CVE-2017-5492 is to update WordPress to version 4.7.1 or later.
Who is affected by CVE-2017-5492?
CVE-2017-5492 affects all WordPress versions prior to 4.7.1.
What type of vulnerability is CVE-2017-5492?
CVE-2017-5492 is a Cross-site request forgery (CSRF) vulnerability.
What does CVE-2017-5492 allow attackers to do?
CVE-2017-5492 allows remote attackers to hijack the authentication of users to perform widget-related actions.