Description
In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.
Remediation
References
Related Vulnerabilities
PHP CVE-2004-1064 Vulnerability (CVE-2004-1064)
WordPress Plugin WordPress Leads Cross-Site Scripting (1.6.2)
PHP Out-of-bounds Write Vulnerability (CVE-2008-2371)
WordPress Plugin Advanced XML Reader XML External Entity Information Disclosure (0.3.4)
WordPress Plugin Companion Sitemap Generator Cross-Site Request Forgery (3.6.6)