Cross-Site Request Forgery Vulnerability in StaffList Plugin for WordPress
CVE-2024-13749

6.1MEDIUM

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
12 February 2025

Summary

The StaffList plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit Cross-Site Request Forgery due to inadequate nonce validation on the 'stafflist' page. This vulnerability permits an attacker to trick an admin into executing actions that could compromise site integrity, such as altering settings or injecting harmful scripts via a crafted request. Site administrators should ensure they update to the latest versions and implement proper security measures to mitigate potential risks.

Affected Version(s)

StaffList * <= 3.2.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Colin Xu
.