CVE-2017-6819: CSRF
In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive use of server resources. The CSRF can trigger an outbound HTTP request for a large file that is then parsed by Press This.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6819?
CVE-2017-6819 is considered a medium severity vulnerability due to its potential to cause excessive resource usage on affected servers.
How do I fix CVE-2017-6819?
To fix CVE-2017-6819, it is recommended to update WordPress to version 4.7.3 or later.
What does CVE-2017-6819 affect?
CVE-2017-6819 affects WordPress versions prior to 4.7.3, specifically targeting the Press This feature.
What kind of attack does CVE-2017-6819 enable?
CVE-2017-6819 enables cross-site request forgery (CSRF) attacks that can trigger excessive HTTP requests.
Who is impacted by CVE-2017-6819?
Any user running WordPress version 4.7.2 or earlier is impacted by CVE-2017-6819.