CVE-2012-1936 describes a Cross-Site Request Forgery (CSRF) vulnerability in WordPress versions 3.3.1 and earlier, stemming from the wp_create_nonce function associating nonces with user accounts rather than sessions. This design flaw could allow remote attackers to conduct CSRF attacks on specific administrative actions by sniffing network traffic. The vulnerability has a CVSS score of 6.8 (Medium), indicating it can be exploited over the network with medium complexity, potentially leading to partial confidentiality, integrity, and availability impacts. While the vendor reportedly disputes its significance, exploit code is publicly available via ExploitDB, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.1CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:1.0:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:1.0.1:*:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:1.0.2:*:*:*:*:*:*:* | ||
1.1.1CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:1.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.