PT-2025-12858 · WordPress · Booknetic

Veshraj Ghimire

·

Publicado

2025-03-26

·

Atualizado

2025-04-30

·

CVE-2024-13146

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Booknetic WordPress plugin versions prior to 4.1.5
Description The issue concerns a lack of CSRF check when creating Staff accounts, which could allow attackers to make logged-in admins add arbitrary Staff members via a CSRF attack. This could potentially be exploited by attackers to add unauthorized staff members.
Recommendations For versions prior to 4.1.5, update to version 4.1.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the Staff account creation feature to minimize the risk of exploitation.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-13146

Produtos afetados

Booknetic