The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin options.
History

Tue, 03 Sep 2024 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Wpwebinfotech
Wpwebinfotech social Auto Poster
CPEs cpe:2.3:a:wpwebinfotech:social_auto_poster:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpwebinfotech
Wpwebinfotech social Auto Poster

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-07-24T02:33:57.454Z

Updated: 2024-08-01T21:41:04.599Z

Reserved: 2024-07-15T13:01:15.191Z

Link: CVE-2024-6751

cve-icon Vulnrichment

Updated: 2024-08-01T21:41:04.599Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-24T03:15:03.810

Modified: 2024-09-03T21:39:06.433

Link: CVE-2024-6751

cve-icon Redhat

No data.