WordPress 3.4.2 cross site request forgery

Description

Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.

ShareShare on FacebookTweet about this on TwitterShare on Google+

Impact
A remote attacker can hijack administrators authentication.

Recommendation
Upgrade to the latest version of Wordpress.

References
CVE-2012-4448
WordPress 3.4.2 Cross Site Request Forgery