WordPress Advanced What should we write next about plugin <=1.0.3 - CSRF to Stored Cross Site Scripting (XSS) vulnerability
CVE-2024-53789

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
2 December 2024

Summary

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Advanced What Should We Write Next About plugin developed by Ritesh Sanap. This security issue allows an attacker to manipulate a user's session and potentially lead to Stored Cross-Site Scripting (XSS) attacks. The vulnerability impacts all versions from n/a through 1.0.3, putting users at risk for unauthorized actions to be performed within the application context. Proper security measures and updates are recommended to mitigate these risks.

Affected Version(s)

Advanced What should we write next about <= 1.0.3

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Chan (Patchstack Alliance)
.