Description
WordPress Plugin Facebook Members is prone to a cross-site request forgery vulnerability. Exploiting this issue may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Facebook Members version 5.0.4 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.0.5 or latest
References
Related Vulnerabilities
WordPress Plugin LazyEater Multiple Unspecified Vulnerabilities (1.2.4)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3553)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-3454)
WordPress Plugin WordPress Landing Pages SQL Injection (1.2.1)
WordPress Plugin Integration for Contact Form 7 and Salesforce Cross-Site Scripting (1.2.4)