CVE-2024-5167 – CM Email Registration Blacklist and Whitelist < 1.4.9 - Add/Delete Emails via CSRF Add and delete any item from blacklist/whitelist
https://notcve.org/view.php?id=CVE-2024-5167
The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which could allow attackers to make a logged in admin add or delete settings from the blacklist or whitelist menu via a CSRF attack El complemento CM Email Registration Blacklist y Whitelist de WordPress anterior a 1.4.9 no tiene verificación CSRF al agregar o eliminar un elemento de la lista negra o blanca, lo que podría permitir a los atacantes hacer que un administrador que haya iniciado sesión agregue o elimine configuraciones de la lista negra o del menú de la lista blanca a través de un ataque CSRF The CM Email Registration Blacklist and Whitelist plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to add and delete emails and modify the blacklist/whitelist via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://wpscan.com/vulnerability/67bb5ab8-4493-4f5b-a989-41576675b61a • CWE-352: Cross-Site Request Forgery (CSRF) •