18 Jan 2017
CVE-2016-6897 - CVE Vulnerability
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896. (CVSS:0.0) (Last Update:2017-01-18)
Vulnerability Details : Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896. Publish Date : 2017-01-18 Last Update Date : 2017-01-18 - CVSS Scores & Vulnerability Types
- Products Affected By CVE-2016-6897
- References For CVE-2016-6897
| ||||||||||||||||||||||||||||||||||||||||||||||||
- Metasploit Modules Related To CVE-2016-6897There are not any metasploit modules related to this CVE entry (Please visit www.metasploit.com for more information) |