Cross-Site Request Forgery (CSRF) Vulnerability in WP Content Copy Protection & No Right Click
CVE-2024-49306

8.8HIGH

Key Information:

Vendor
WP-buy
Status
WP Content Copy Protection & No Right Click
Vendor
CVE Published:
20 October 2024

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Content Copy Protection & No Right Click plugin, allowing attackers to exploit the plugin's functionalities. This vulnerability affects versions up to 3.5.9, potentially enabling unauthorized actions to be performed without the end user's consent. Proper validation and security measures are essential to protect users against this type of attack.

Affected Version(s)

WP Content Copy Protection & No Right Click <= 3.5.9

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.