CVE-2024-5028
CM WordPress Search And Replace Plugin < 1.3.9 - Plugin Reset via CSRF
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
13 jul 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Productos afectados
Unknown · CM WordPress Search And Replace Plugin