Cross-Site Request Forgery Vulnerability in BA Book Everything Plugin
CVE-2024-8795
What is CVE-2024-8795?
The BA Book Everything plugin for WordPress has a vulnerability that allows unauthenticated attackers to exploit Cross-Site Request Forgery. This flaw exists in all versions up to and including 1.6.20, stemming from inadequate nonce validation in the my_account_update() function. Attackers can potentially manipulate a site administrator into triggering an action, such as clicking on a deceptive link, which could lead to unauthorized updates to user account details. Exploiting this vulnerability may enable an attacker to reset a user's password, providing them unauthorized access to accounts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BA Book Everything * <= 1.6.20
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved