Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No reference.
Fri, 04 Oct 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Visual Sound <= 1.03 - Cross-Site Request Forgery to Settings Update | |
Weaknesses | CWE-352 | |
References |
|
|
Metrics |
cvssV3_1
|
Fri, 04 Oct 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Visual Sound plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.03. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-7859. Reason: This candidate is a reservation duplicate of CVE-2024-7859. Notes: All CVE users should reference CVE-2024-7859 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. |
Tue, 27 Aug 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 27 Aug 2024 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Visual Sound plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.03. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
Title | Visual Sound <= 1.03 - Cross-Site Request Forgery to Settings Update | |
Weaknesses | CWE-352 | |
References |
| |
Metrics |
cvssV3_1
|

Status: REJECTED
Assigner: Wordfence
Published:
Updated: 2024-10-04T15:42:35.511Z
Reserved: 2024-08-26T22:32:57.990Z
Link: CVE-2024-8197

Updated:

Status : Rejected
Published: 2024-08-27T11:15:05.087
Modified: 2024-10-04T16:15:03.603
Link: CVE-2024-8197

No data.

No data.