DescriptionCross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wordpress (PTS)wheezy3.6.1+dfsg-1~deb7u10vulnerable
wheezy (security)3.6.1+dfsg-1~deb7u20vulnerable
jessie (security)4.1+dfsg-1+deb8u16vulnerable
stretch (security), stretch4.7.5+dfsg-2+deb9u2vulnerable
buster, sid4.9.4+dfsg-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs


issue only allows comments from posts to be moved to "needs moderation" list

Search for package or bug name: Reporting problems