Description
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix settings, which could allow attackers to make logged admins perform such action via a CSRF attack
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10543 | The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix settings, which could allow attackers to make logged admins perform such action via a CSRF attack |
References
History
Tue, 22 Apr 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ngothang
Ngothang wp Multitasking |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:ngothang:wp_multitasking:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Ngothang
Ngothang wp Multitasking |
Wed, 09 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 09 Apr 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix settings, which could allow attackers to make logged admins perform such action via a CSRF attack | |
| Title | WP MultiTasking <= 0.1.12 - Permalink Suffix Update via CSRF | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-09T19:11:40.133Z
Reserved: 2024-07-17T20:31:58.322Z
Link: CVE-2024-6860
Updated: 2025-04-09T19:11:13.488Z
Status : Analyzed
Published: 2025-04-09T06:15:41.177
Modified: 2025-04-22T17:20:54.420
Link: CVE-2024-6860
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD