CVE-2019-6030
HIGH WAF: Low
CVSS 8.8
Published: 2019-12-26
CWE-352
Cross-site request forgery (CSRF) vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
WAF Coverage Analysis
Cross-Site Request Forgery (CSRF)
Low WAF Coverage
OWASP: A01:2021 Broken Access Control
Affected Software
| Vendor | Product | Version |
|---|---|---|
| custom_body_class_project | custom_body_class | up to 0.6.0 |
References
- jvn.jp (Third Party Advisory)
- wordpress.org (Release Notes, Vendor Advisory)