CVE-2024-29773
WordPress BizPrint plugin <= 4.5.5 - CSRF to XSS vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-Site Request Forgery (CSRF) vulnerability in BizSwoop a CPF Concepts, LLC Brand BizPrint allows Cross-Site Scripting (XSS).This issue affects BizPrint: from n/a through 4.5.5.
Vulnerabilidad de Cross-Site Request Forgery (CSRF) en BizSwoop a CPF Concepts, LLC Brand BizPrint permite cross-site scripting (XSS). Este problema afecta a BizPrint: desde n/a hasta 4.5.5.
The BizPrint plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5.5. This is due to missing or incorrect nonce validation in the process.php file. This makes it possible for unauthenticated attackers to generate invoices containing malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. While the Cross-Site Request Forgery vulnerability was patched in version 4.5.4, making exploitation of cross-site scripting impractical, user inputs were not completely sanitized until version 4.5.6
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-03-19 CVE Reserved
- 2024-03-25 CVE Published
- 2024-03-28 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
- CAPEC-63: Cross-Site Scripting (XSS)
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/print-google-cloud-print-gcp-woocommerce/wordpress-bizprint-plugin-4-5-5-csrf-to-xss-vulnerability?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Print Google Cloud Print Gcp Woocommerce Search vendor "Print Google Cloud Print Gcp Woocommerce" | Print Google Cloud Print Gcp Woocommerce Search vendor "Print Google Cloud Print Gcp Woocommerce" for product "Print Google Cloud Print Gcp Woocommerce" | >= 0.0.0 <= 4.5.4 Search vendor "Print Google Cloud Print Gcp Woocommerce" for product "Print Google Cloud Print Gcp Woocommerce" and version " >= 0.0.0 <= 4.5.4" | en |
Affected
|