Description
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
Remediation
References
Related Vulnerabilities
WordPress Plugin HTML5 Video Player-Best WordPress Video Player and Block SQL Injection (2.5.26)
Envoy Proxy Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-15225)
WordPress Plugin VideoWhisper Video Conference Integration Arbitrary File Upload (4.91.8)
WordPress Plugin CYSTEME Finder, the admin files explorer Cross-Site Request Forgery (1.4)