First published: Thu Aug 08 2019(Updated: )
The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php CSRF.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mijnpress Admin-renamer-extended | =3.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14680 is considered a medium severity vulnerability due to its potential for cross-site request forgery (CSRF) attacks.
To fix CVE-2019-14680, update the Admin renamer extended plugin to the latest version available or disable the plugin if an update is not possible.
CVE-2019-14680 affects users of the Admin renamer extended plugin version 3.2.1 for WordPress.
CVE-2019-14680 is a cross-site request forgery (CSRF) vulnerability that allows unauthorized actions in WordPress.
A workaround for CVE-2019-14680 includes manually disabling the plugin until an update can be applied.