CVE-2024-4204
Bulk Posts Editing For WordPress <= 4.2.3 - Cross-Site Request Forgery
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to missing or incorrect nonce validation on the plugin's AJAX actions.. This makes it possible for unauthenticated attackers to create and duplicate posts, retrieve post content, and modify post taxonomy among other things via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
El complemento para WordPress Bulk Posts Editing For WordPress es vulnerable a Cross-Site Request Forgery en todas las versiones hasta la 4.2.3 incluída. Esto se debe a una validación nonce faltante o incorrecta en las acciones AJAX del complemento. Esto hace posible que atacantes no autenticados creen y dupliquen publicaciones, recuperen el contenido de las publicaciones y modifiquen la taxonomía de las publicaciones, entre otras cosas, a través de una solicitud falsificada, siempre que puedan engañar a un sitio. administrador para que realice una acción como hacer clic en un enlace.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-04-25 CVE Reserved
- 2024-05-16 CVE Published
- 2024-08-01 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ithemelandco Search vendor "Ithemelandco" | Bulk Posts Editing For WordPress Search vendor "Ithemelandco" for product "Bulk Posts Editing For WordPress" | <= 4.2.3 Search vendor "Ithemelandco" for product "Bulk Posts Editing For WordPress" and version " <= 4.2.3" | en |
Affected
|