CSRF to HTML Injection in Comments
High
W
WordPress
Submitted None
Team Summary
Official summary from WordPress
Simon discovered a CSRF vulnerability that led to RCE. More [details are available on the RIPS blog](https://blog.ripstech.com/2019/wordpress-csrf-to-rce/).
Actions:
Reported by
simonscannell
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Cross-Site Request Forgery (CSRF)