Cross-Site Request Forgery in Nokaut Offers Box Plugin for WordPress
CVE-2024-10634
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 15 May 2025
Badges
What is CVE-2024-10634?
The Nokaut Offers Box WordPress plugin version 1.4.0 is susceptible to Cross-Site Request Forgery (CSRF) attacks due to a missing CSRF check in its settings update functionality. This flaw can allow attackers to trick authenticated administrators into executing unintended actions without their consent, thereby compromising the integrity of the plugin and potentially affecting the overall security of the WordPress site. It is crucial for users to ensure proper security measures are in place to mitigate such risks.
Affected Version(s)
Nokaut Offers Box 0 <= 1.4.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved