CVE-2019-11590: CSRF
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $POST['action'] value and the $GET['action'] value, and the latter is unsanitized.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11590?
CVE-2019-11590 refers to a vulnerability in the 10Web Form Maker plugin for WordPress that allows cross-site request forgery (CSRF).
How does CVE-2019-11590 affect WordPress sites?
CVE-2019-11590 can be exploited to perform CSRF attacks on WordPress sites that have the vulnerable 10Web Form Maker plugin installed.
What is the severity of CVE-2019-11590?
CVE-2019-11590 has a severity rating of 8.8, which is considered high.
How can I fix the CVE-2019-11590 vulnerability?
To fix the CVE-2019-11590 vulnerability, you should update the 10Web Form Maker plugin to version 1.13.5 or newer.
Where can I find more information about CVE-2019-11590?
You can find more information about CVE-2019-11590 on the following sources: [1] [2] [3]