Cross-Site Request Forgery Vulnerability Affects Most And Least Read Posts Widget
CVE-2024-49628

8.8HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
20 October 2024

Summary

The Cross-Site Request Forgery (CSRF) vulnerability in WhileTrue's Most And Least Read Posts Widget poses significant security risks, allowing attackers to forge requests on behalf of authenticated users. This vulnerability compromises the integrity of requests made by legitimate users, which can lead to unauthorized actions being executed without user consent. It affects all versions of the widget from the earliest release through version 2.5.18, necessitating immediate attention from website administrators to safeguard their installations against this exploit.

Affected Version(s)

Most And Least Read Posts Widget <= 2.5.18

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SOPROBRO (Patchstack Alliance)
.