Cross-Site Request Forgery (CSRF) Vulnerability in WP Content Copy Protection & No Right Click
CVE-2024-49306
8.8HIGH
Key Information:
- Vendor
- WP-buy
- Status
- WP Content Copy Protection & No Right Click
- Vendor
- CVE Published:
- 20 October 2024
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Content Copy Protection & No Right Click plugin, allowing attackers to exploit the plugin's functionalities. This vulnerability affects versions up to 3.5.9, potentially enabling unauthorized actions to be performed without the end user's consent. Proper validation and security measures are essential to protect users against this type of attack.
Affected Version(s)
WP Content Copy Protection & No Right Click <= 3.5.9
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)