Description
WordPress is prone to same origin method execution (SOME) vulnerability. The impact of a SOME attack is similar to the impact of cross-site scripting, though there are some important and distinguishing exploitation restrictions. An attacker may leverage this issue to hijack dangerous web functionality and even exfiltrate sensitive user data. WordPress versions 4.1.x ranging from 4.1 and up to (and including) 4.1.10 are vulnerable.
Remediation
Update to WordPress version 4.1.11 or latest
References
https://gist.github.com/cure53/09a81530a44f6b8173f545accc9ed07e
https://hackerone.com/reports/134738
http://www.benhayak.com/2015/06/same-origin-method-execution-some.html
Related Vulnerabilities
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-37277)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery SQL Injection (1.3.29)
Magento Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-7892)
MySQL CVE-2012-0489 Vulnerability (CVE-2012-0489)
WordPress Plugin Co-Authors Plus Multiple Unspecified Vulnerabilities (3.1.2)