Vulnerability Details CVE-2013-2699
Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote attackers to hijack the authentication of administrators for requests that deactivate a plugin via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.0%
CVSS Severity
CVSS v2 Score 6.8
Products affected by CVE-2013-2699
-
cpe:2.3:a:underconstruction_project:underconstruction:-
-
cpe:2.3:a:underconstruction_project:underconstruction:1.0
-
cpe:2.3:a:underconstruction_project:underconstruction:1.01
-
cpe:2.3:a:underconstruction_project:underconstruction:1.02
-
cpe:2.3:a:underconstruction_project:underconstruction:1.03
-
cpe:2.3:a:underconstruction_project:underconstruction:1.04
-
cpe:2.3:a:underconstruction_project:underconstruction:1.05
-
cpe:2.3:a:underconstruction_project:underconstruction:1.06
-
cpe:2.3:a:underconstruction_project:underconstruction:1.07
-
cpe:2.3:a:underconstruction_project:underconstruction:1.08