Cross-Site Request Forgery in Apptivo Business Site CRM Plugin for WordPress
CVE-2024-13405
4.3MEDIUM
What is CVE-2024-13405?
The Apptivo Business Site CRM plugin for WordPress exhibits a vulnerability that allows Cross-Site Request Forgery (CSRF) attacks due to improper nonce validation on the 'awp_ip_deny' page. This flaw enables unauthenticated attackers to manipulate the plugin’s functionality by tricking site administrators into executing malicious actions, such as clicking on deceptive links, leading to unauthorized blocking of IP addresses. It is essential for administrators using this plugin to implement adequate security measures to safeguard against potential exploitation.
Affected Version(s)
Apptivo Business Site CRM * <= 5.3