Cross-site request forgery (CSRF) vulnerability in the options admin page in the WP-PostViews plugin before 1.63 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.
2014-04-10T20:29:20.267
2025-04-12T10:46:40.837
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | lesterchan | wp-postviews | ≤ 1.62 | Yes |
| Application | lesterchan | wp-postviews | 1.00 | Yes |
| Application | lesterchan | wp-postviews | 1.01 | Yes |
| Application | lesterchan | wp-postviews | 1.02 | Yes |
| Application | lesterchan | wp-postviews | 1.10 | Yes |
| Application | lesterchan | wp-postviews | 1.11 | Yes |
| Application | lesterchan | wp-postviews | 1.20 | Yes |
| Application | lesterchan | wp-postviews | 1.30 | Yes |
| Application | lesterchan | wp-postviews | 1.31 | Yes |
| Application | lesterchan | wp-postviews | 1.40 | Yes |
| Application | lesterchan | wp-postviews | 1.50 | Yes |
| Application | lesterchan | wp-postviews | 1.60 | Yes |
| Application | lesterchan | wp-postviews | 1.61 | Yes |