@f41z4n on WordPress.org
Created ticket #57451 on Core Trac:Cross Site Request Forgery on Admin of any wordpress site to export files
Created ticket #57437 on Core Trac:Insecure Direct Object Reference in "author" parameter while making a ...