CSRF Vulnerability in WordPress Filesystem Credentials Dialog

CSRF Vulnerability in WordPress Filesystem Credentials Dialog

CVE-2017-9064 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.

Learn more about our Wordpress Pen Testing.