Cross-Site Request Forgery Vulnerability in SliceWP Affiliates Plugin for WordPress
CVE-2024-12454

6.1MEDIUM

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
18 December 2024

What is CVE-2024-12454?

CVE-2024-12454 identifies a critical Cross-Site Request Forgery (CSRF) vulnerability in the SliceWP Affiliates plugin for WordPress. All versions up to and including 1.1.23 are affected due to inadequate nonce validation in key functions. This flaw allows unauthenticated attackers to exploit the vulnerability by tricking a victim, typically a site administrator, into executing unintended actions—such as clicking on malicious links. The consequence of such an exploit could lead to unauthorized changes within the WordPress environment, highlighting the necessity for immediate updates to ensure site integrity and security.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.