CVE-2012-5387, CVE-2012-5388
The White Label CMS plugin before version 1.5.1 contains a cross-site request forgery vulnerability in wlcms-plugin.php that allows attackers to hijack administrator authentication and modify the developer name setting through the wlcms_o_developer_name parameter. An attacker could exploit this by crafting a malicious request to wp-admin/admin.php that includes XSS code within the developer name field, potentially compromising administrative functions. The vulnerability affects all versions before 1.5.1 and is resolved in that version and later.
Based on public CVE data (MITRE/NVD).