CVE-2007-1244

Source
https://cve.org/CVERecord?id=CVE-2007-1244
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2007-1244.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2007-1244
Downstream
Published
2007-03-03T19:19:00Z
Modified
2026-04-10T03:38:44.324419Z
Summary
[none]
Details

Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.

References

Affected packages