Cross-Site Request Forgery Vulnerability in Comments Extra Fields for WordPress
CVE-2024-0830
4.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 13 March 2024
What is CVE-2024-0830?
The Comments Extra Fields For Post, Pages and CPT plugin for WordPress is affected by a Cross-Site Request Forgery vulnerability due to inadequate nonce validation across multiple AJAX actions. This issue allows unauthenticated attackers to send crafted requests to the WordPress site, potentially tricking site administrators into executing harmful actions, such as altering comment form fields and manipulating plugin settings. Implementing proper nonce validation is essential to mitigate this risk and ensure the security of the affected plugin.
Affected Version(s)
Comments Extra Fields For Post,Pages and CPT * <= 5.0