High severity8.0NVD Advisory· Published Sep 18, 2017· Updated May 13, 2026
CVE-2017-14530
CVE-2017-14530
Description
WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.
Affected products
1- cpe:2.3:a:crony_cronjob_manager_project:crony_cronjob_manager:*:*:*:*:*:wordpress:*:*Range: <=0.4.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- cybersecurityworks.com/zerodays/cve-2017-14530-crony.htmlnvdExploitThird Party Advisory
- github.com/cybersecurityworks/Disclosed/issues/9nvdExploitTechnical DescriptionThird Party Advisory
- wordpress.org/plugins/crony/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.