← Back

CVE-2024-6751

nvd nist
Published: Jul 24, 2024Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin options.

Affected (1)

1 product
Social Auto Poster
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.3.15

Timeline

No history available yet.