Cross-Site Request Forgery Vulnerability in Admin SMS Alert by Scott E. Royalty
CVE-2024-51637

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 November 2024

What is CVE-2024-51637?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Admin SMS Alert plugin, developed by Scott E. Royalty, that could allow attackers to execute unauthorized actions on behalf of an authenticated user. This vulnerability can lead to a stored cross-site scripting (XSS) scenario, where malicious scripts can be injected and stored within the application, posing a significant risk to users who interact with the compromised functionality. The issue affects Admin SMS Alert versions from n/a through 1.1.0, underscoring the importance of timely updates and vigilant security practices.

Affected Version(s)

Admin SMS Alert 0 <= 1.1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.