Cross-Site Request Forgery Vulnerability in DirectoryPress Frontend Plugin for WordPress
CVE-2024-10581
4.3MEDIUM
What is CVE-2024-10581?
The DirectoryPress Frontend plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit Cross-Site Request Forgery due to improper nonce validation in the dpfl_listingStatusChange()
function. This vulnerability enables attackers to manipulate listing statuses by tricking site administrators into executing actions through deceptive links, even without proper authentication.
Affected Version(s)
DirectoryPress Frontend * <= 2.7.9