Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-0592

Опубликовано: 13 мар. 2024
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the handle_create_link() function. This makes it possible for unauthenticated attackers to add related posts to other posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This ultimately makes it possible for attackers to view draft and password protected posts.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:never5:related_posts:*:*:*:*:*:wordpress:*:*
Версия до 2.2.2 (исключая)

EPSS

Процентиль: 34%
0.00135
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 5.4
github
почти 2 года назад

The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the handle_create_link() function. This makes it possible for unauthenticated attackers to add related posts to other posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This ultimately makes it possible for attackers to view draft and password protected posts.

EPSS

Процентиль: 34%
0.00135
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-352