The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin perform such action via a CSRF attack
History

Thu, 07 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N'}


Wed, 06 Nov 2024 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
CPEs cpe:2.3:a:shaon:post_from_frontend:*:*:*:*:*:wordpress:*:*

Tue, 05 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Shaon
Shaon post From Frontend
CPEs cpe:2.3:a:shaon:post_from_frontend:*:*:*:*:*:*:*:*
Vendors & Products Shaon
Shaon post From Frontend
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 05 Nov 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin perform such action via a CSRF attack
Title Post From Frontend <= 1.0.0 - Post Deletion via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-11-05T06:00:08.314Z

Updated: 2024-11-07T19:56:59.998Z

Reserved: 2024-10-09T13:33:36.680Z

Link: CVE-2024-9689

cve-icon Vulnrichment

Updated: 2024-11-05T15:40:25.747Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-05T06:15:06.360

Modified: 2024-12-20T18:59:47.850

Link: CVE-2024-9689

cve-icon Redhat

No data.