CVE Database /
CVE-2017-18510
CVE · High
CVE-2017-18510 — Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager [custom-sidebars] < 3.1.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2017-18510
|
Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager [custom-sidebars] < 3.1.0 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 3.1.0
|
3.1.0 |
2017-10-04 |
—
|
CVE-2017-18510
The Custom Sidebars plugin prior to version 3.1.0 contains cross-site request forgery vulnerabilities affecting the set location functionality as well as import and export operations. An attacker could exploit these CSRF flaws to perform unauthorized actions on behalf of authenticated users without their knowledge or consent.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings