Description
WordPress Plugin Mingle Forum is prone to multiple cross-site request forgery vulnerabilities. Exploiting these issues may allow a remote attacker to perform certain administrative actions and gain unauthorized access to the affected application; other attacks are also possible. WordPress Plugin Mingle Forum version 1.0.34 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.0 or latest
References
Related Vulnerabilities
WordPress Plugin Email Queue by BestWebSoft Cross-Site Request Forgery (1.0.0)
Joomla! Core 1.5.x Security Bypass (1.5.0 - 1.5.5)
Joomla! Core 1.5.12 Arbitrary File Upload (1.5.12)
WordPress 4.5.x Multiple Vulnerabilities (4.5 - 4.5.5)
Serendipity URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-5474)