WordPress Sogrid plugin <= 1.5.2 - CSRF to Privilege Escalation vulnerability
CVE-2024-54352
8.8HIGH
Summary
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in Sogrid, a product by Sabri Taieb. This security flaw allows an attacker to perform actions on behalf of an authenticated user, potentially leading to privilege escalation. The vulnerability impacts Sogrid versions prior to and including 1.5.2, posing significant security risks for users. It is crucial for organizations using this product to assess their exposure and take necessary steps to mitigate the vulnerability.
Affected Version(s)
Sogrid <= 1.5.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)