WordPress Push Monkey Pro plugin <= 3.9 - CSRF to Stored XSS vulnerability
CVE-2024-54386

7.1HIGH

Key Information:

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart applications developed by Get Push Monkey LLC. This vulnerability allows unauthorized commands to be transmitted from a user that the web application trusts. Specifically, it affects versions from n/a through 3.9, potentially compromising sensitive user actions. Websites utilizing this software should immediately assess their exposure to this security issue to secure their web applications from unauthorized access and malicious actions.

Affected Version(s)

Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart <= 3.9

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhamad Agil Fachrian (Patchstack Alliance)
.