CVE-2012-5387, CVE-2012-5388
The White Label CMS plugin before version 1.5.1 contains a cross-site request forgery vulnerability in its wlcms-plugin.php file that allows attackers to perform unauthorized actions on behalf of administrators. An attacker can craft a malicious request to modify the developer name setting through the wlcms_o_developer_name parameter, potentially injecting cross-site scripting code into the application. This vulnerability affects the plugin's save functionality accessed via wp-admin/admin.php and compromises the security of administrator sessions.
Based on public CVE data (MITRE/NVD).