Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T18:43:56.450Z

Reserved: 2017-08-07T00:00:00

Link: CVE-2017-12651

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-08-07T17:29:00.567

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-12651

cve-icon Redhat

No data.