First published: Sun Mar 12 2017(Updated: )
In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive use of server resources. The CSRF can trigger an outbound HTTP request for a large file that is then parsed by Press This.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=4.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6819 is considered a medium severity vulnerability due to its potential to cause excessive resource usage on affected servers.
To fix CVE-2017-6819, it is recommended to update WordPress to version 4.7.3 or later.
CVE-2017-6819 affects WordPress versions prior to 4.7.3, specifically targeting the Press This feature.
CVE-2017-6819 enables cross-site request forgery (CSRF) attacks that can trigger excessive HTTP requests.
Any user running WordPress version 4.7.2 or earlier is impacted by CVE-2017-6819.