What this actually is.
Technical background, root cause, and affected surface.
WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.
- Vendor
- Crony
- Affected Product
- Crony_Cronjob_Manager
- CVE
- CVE-2017-14530
- Securin ID
- 2015-CSW-10-1011
- Status
- Fixed
- Date
- August 28, 2015
- Severity
- High
- CVSS Score
- 8
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-352
From one request
to root shell.
Reproduced in a sandboxed environment. Requires only LAN or WiFi adjacency.
What an attacker does to you.
Post-exploitation outcomes mapped to CVSS impact metrics.
An attacker can exploit this by persuading a user of the interface to follow a malicious link, to allow the attacker to perform arbitrary actions with the privilege level of the affected user.
Fix it. In this order.
A runbook, not a checklist. Sequence matters — assume compromise before you act.
Download the latest updated version from vendor advisory and update.
disclose@securin.ioVendors moved in days.
Attackers in hours.
Reconstructed from vendor advisories, CISA bulletins, and Securin research records.
Discovered in Crony Cronjob Manager Version 0.4.4.
Reported to the vendor
Vendor acknowledged the report
Issues fixed in version 0.4.6.
Timeline recorded · Disclosure coordinated by Securin
Cite, verify, go deeper.
Primary sources — NVD, CISA KEV, and machine-readable IoC feed.