CVE-2019-17675

HIGH8.8EPSS 0.92%
Published: 10/17/2019Modified: 5/27/2026
Also known as:DEBIAN-CVE-2019-17675

Description

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.8CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References (1)