Cross-Site Request Forgery Risk in Cost Calculator Builder Plugin for WordPress
CVE-2024-10892

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
18 December 2024

What is CVE-2024-10892?

The Cost Calculator Builder plugin for WordPress, prior to version 3.2.43, is vulnerable to Cross-Site Request Forgery (CSRF). This vulnerability arises due to the lack of proper CSRF checks in certain AJAX actions. attackers can exploit this weakness to trick authenticated users into executing potentially harmful actions without their consent. It is crucial for users and administrators of this plugin to update to the latest version to mitigate this risk.

References

Timeline

  • Vulnerability published

.