AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-6797

MEDIUM · CVSS 6.8 EPSS 2.88%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2013-11-19 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2013-6797
Severity
MEDIUM
CVSS
6.8
EPSS
2.88%
WordPress Java

Original NVD Description

Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin before 2.0.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that embed arbitrary URLs via the bw_url parameter in the bw-videos page to wp-admin/admin.php, as demonstrated by embedding a URL to a JavaScript file.