WordPress Push Monkey Pro plugin <= 3.9 - CSRF to Stored XSS vulnerability
CVE-2024-54386
7.1HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 16 December 2024
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart applications developed by Get Push Monkey LLC. This vulnerability allows unauthorized commands to be transmitted from a user that the web application trusts. Specifically, it affects versions from n/a through 3.9, potentially compromising sensitive user actions. Websites utilizing this software should immediately assess their exposure to this security issue to secure their web applications from unauthorized access and malicious actions.
Affected Version(s)
Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart <= 3.9
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Muhamad Agil Fachrian (Patchstack Alliance)