[wp-trac] [WordPress Trac] #23004: Editor CSRF vulnerabilities discovered

WordPress Trac noreply at wordpress.org
Wed Dec 19 13:21:31 UTC 2012


#23004: Editor CSRF vulnerabilities discovered
--------------------------+------------------------------
 Reporter:  drssay        |       Owner:
     Type:  defect (bug)  |      Status:  new
 Priority:  normal        |   Milestone:  Awaiting Review
Component:  General       |     Version:  3.5
 Severity:  critical      |  Resolution:
 Keywords:                |
--------------------------+------------------------------

Comment (by TobiasBg):

 Where did you get the value "7258002722" for the {{{_wpnonce}}} parameter
 from?

 Copy/paste from a session when you where logged in as admin? That doesn't
 count then.

 And: Next time please do not report security vulnerabilities here, but by
 following the instructions at http://codex.wordpress.org/FAQ_Security

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/23004#comment:1>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list