Total vulnerabilities in the database
In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-this.php), leading to excessive use of server resources. The CSRF can trigger an outbound HTTP request for a large file that is then parsed by Press This.
Software | From | Fixed in |
---|---|---|
WordPress / wordpress | - | 4.7.2.x |