Description Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin. Remediation References CVE-2017-5476 Related Vulnerabilities ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-2050) WordPress Plugin Ultimate Maps by Supsystic Cross-Site Scripting (1.2.4) WordPress Plugin UserPro-Community and User Profile Privilege Escalation (4.9.27) MathJax Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-1999024) WordPress Plugin Responsive Clients Logo Gallery for WordPress-Smart Logo Showcase Lite includes Backdoor [Only if downloaded via the vendor website] (1.1.7) Severity High Classification CVE-2017-5476 CWE-352 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities