Description
WordPress Plugin LayerSlider is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin LayerSlider version 4.6.1 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 5.0.0 or latest
References
http://www.intelligentexploit.com/view-details.html?id=18679
http://packetstormsecurity.com/files/125637/WordPress-LayerSlider-4.6.1-CSRF-Traversal.html
Related Vulnerabilities
WordPress Plugin WP-SpamFree Anti-Spam Cross-Site Scripting (2.1.1.6)
Dotclear Other Vulnerability (CVE-2006-2866)
Dolibarr Missing Authorization Vulnerability (CVE-2018-10092)
WordPress Plugin IP Geo Block Security Bypass (2.2.2)
TYPO3 URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2010-3661)