Description
wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.
Remediation
References
Related Vulnerabilities
Grafana Incorrect Authorization Vulnerability (CVE-2021-28146)
WordPress Plugin Smooth Scroll Page Up/Down Buttons Cross-Site Scripting (1.3)
WordPress Plugin CMS Tree Page View 'cms_tpv_view' Parameter Cross-Site Scripting (0.8.8)
WordPress Plugin Daily Prayer Time Cross-Site Request Forgery (2023.03.08)
WordPress Plugin FireCask Like & Share Button Cross-Site Scripting (1.1.5)