Cross-Site Request Forgery Vulnerability in StaffList Plugin for WordPress
CVE-2024-13749
6.1MEDIUM
Summary
The StaffList plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit Cross-Site Request Forgery due to inadequate nonce validation on the 'stafflist' page. This vulnerability permits an attacker to trick an admin into executing actions that could compromise site integrity, such as altering settings or injecting harmful scripts via a crafted request. Site administrators should ensure they update to the latest versions and implement proper security measures to mitigate potential risks.
Affected Version(s)
StaffList * <= 3.2.3
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Colin Xu