cpe:/a:wordpress:wordpress CVE-2008-0198 2008-01-09T19:46:00.000-05:00 2008-09-05T17:34:27.123-04:00 4.3 NETWORK MEDIUM NONE NONE PARTIAL NONE http://nvd.nist.gov 2008-01-10T11:48:00.000-05:00 BUGTRAQ 20080103 securityvulns.com russian vulnerabilities digest SREASON 3539 MISC http://securityvulns.ru/Sdocument546.html MISC http://securityvulns.ru/Sdocument667.html MISC http://websecurity.com.ua/1600/ MISC http://websecurity.com.ua/1641/ Multiple cross-site request forgery (CSRF) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) wpcf_question, (2) wpcf_success_msg, or (3) wpcf_error_msg parameter to wp-admin/admin.php.