The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 May 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Robbychen
Robbychen simple Buttons Creator |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:robbychen:simple_buttons_creator:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Robbychen
Robbychen simple Buttons Creator |
Fri, 09 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-09T18:43:11.239Z
Reserved: 2024-03-23T17:39:44.424Z
Link: CVE-2024-2857
Updated: 2024-08-01T19:25:42.160Z
Status : Analyzed
Published: 2024-04-15T05:15:15.310
Modified: 2025-05-08T20:31:29.077
Link: CVE-2024-2857
No data.
OpenCVE Enrichment
No data.