Description
Cross-site request forgery (CSRF) vulnerability in the AdminPanel in WordPress 2.1.1 and earlier allows remote attackers to perform privileged actions as administrators, as demonstrated using the delete action in wp-admin/post.php. NOTE: this issue can be leveraged to perform cross-site scripting (XSS) attacks and steal cookies via the post parameter.
Remediation
References
Related Vulnerabilities
Joomla Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2008-3227)
Joomla Exposure of Resource to Wrong Sphere Vulnerability (CVE-2020-10238)
WordPress Plugin WP Data Access SQL Injection (4.3.1)
WordPress Plugin VideoWhisper Video Presentation 'vw_upload.php' Arbitrary File Upload (3.17)