CVE-2019-12826
Summary
| CVE | CVE-2019-12826 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-01 18:15:00 UTC |
| Updated | 2019-07-31 08:15:00 UTC |
| Description | A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility) by crafting a malicious POST request that tricks administrators into adding the code. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wpchef | Widget Logic | All | All | All | All |
| Application | Wpchef | Widget Logic | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Widget Logic <= 5.10.2 - CSRF and Lack of Authorisation | MISC | wpvulndb.com | |
| Widget Logic <= 5.9.0 - CSRF to RCE | MISC | wpvulndb.com | |
| Widget Logic <= 5.9.0 CSRF to RCE (CVE-2019-12826) | MISC | dannewitz.ninja | Exploit, Third Party Advisory |
| 403 Forbidden | CONFIRM | plugins.trac.wordpress.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.