Cross-Site Request Forgery in MemorialDay Plugin for WordPress
CVE-2024-13523
5.4MEDIUM
What is CVE-2024-13523?
The MemorialDay plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF) attacks due to inadequate nonce validation in its functionality. This vulnerability allows attackers to forge requests, posing a security threat by potentially manipulating plugin settings or injecting harmful scripts, provided they can deceive a site administrator into executing specific actions, such as clicking on a malicious link.
Affected Version(s)
MemorialDay * <= 1.0.4