BugTraq
Cross-Site Request Forgery vulnerability in Email Users WordPress Plugin Aug 15 2016 04:18PM
Summer of Pwnage (lists securify nl)
------------------------------------------------------------------------

Cross-Site Request Forgery vulnerability in Email Users WordPress Plugin
------------------------------------------------------------------------

Julien Rentrop, July 2016

------------------------------------------------------------------------

Abstract
------------------------------------------------------------------------

It was found that the Email Users WordPress Plugin is vulnerable to
Cross-Site Request Forgery. By using this issue it is possible for an
attacker to send arbitrary (bulk) email messages to any address. In
order to exploit this issue, an attacker needs to lure a target user
into clicking a specially crafted link or visiting a malicious website
(or advertisement).

------------------------------------------------------------------------

OVE ID
------------------------------------------------------------------------

OVE-20160718-0001

------------------------------------------------------------------------

Tested versions
------------------------------------------------------------------------

This issue was successfully tested on Email Users WordPress Plugin
version 4.8.3.

------------------------------------------------------------------------

Fix
------------------------------------------------------------------------

This issue is resolved in Email Users version 4.8.4.

------------------------------------------------------------------------

Details
------------------------------------------------------------------------

https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_vulnerabili
ty_in_email_users_wordpress_plugin.html

------------------------------------------------------------------------

Summer of Pwnage (https://sumofpwn.nl) is a Dutch community project. Its
goal is to contribute to the security of popular, widely used OSS
projects in a fun and educational way.

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus