A cross-site request forgery that could be used to trick a user into changing their password.
See https://wordpress.org/news/2014/11/wordpress-4-0-1/
This vulnerability affects the following application versions:
- WordPress 3.7.4
- WordPress 3.8.4
- WordPress 3.9.2
- WordPress 4.0