Cross-Site Request Forgery Vulnerability Affects Most And Least Read Posts Widget
CVE-2024-49628
8.8HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 20 October 2024
Summary
The Cross-Site Request Forgery (CSRF) vulnerability in WhileTrue's Most And Least Read Posts Widget poses significant security risks, allowing attackers to forge requests on behalf of authenticated users. This vulnerability compromises the integrity of requests made by legitimate users, which can lead to unauthorized actions being executed without user consent. It affects all versions of the widget from the earliest release through version 2.5.18, necessitating immediate attention from website administrators to safeguard their installations against this exploit.
Affected Version(s)
Most And Least Read Posts Widget <= 2.5.18
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
SOPROBRO (Patchstack Alliance)