The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or incorrect nonce validation on the categorifyAjaxUpdateFolderPosition function. This makes it possible for unauthenticated attackers to update the folder position of categories as well as update the metadata of other taxonomies via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
History

Tue, 07 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Frenify
Frenify categorify
Weaknesses CWE-352
CPEs cpe:2.3:a:frenify:categorify:*:*:*:*:*:wordpress:*:*
Vendors & Products Frenify
Frenify categorify

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-02-27T11:05:07.777Z

Updated: 2024-08-01T18:56:22.567Z

Reserved: 2024-02-26T22:26:07.243Z

Link: CVE-2024-1912

cve-icon Vulnrichment

Updated: 2024-08-01T18:56:22.567Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-27T11:15:09.610

Modified: 2025-01-07T14:24:01.063

Link: CVE-2024-1912

cve-icon Redhat

No data.