PT-2024-15993 · WordPress · Transients Manager

Batfeats

+1

·

Published

2024-10-23

·

Updated

2024-10-25

·

CVE-2024-10045

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Transients Manager plugin for WordPress version 2.0.6 and earlier
Description The issue is due to missing or incorrect nonce validation on the process actions function, making it possible for unauthenticated attackers to delete transients via a forged request if they can trick a site administrator into performing an action such as clicking on a link.
Recommendations For Transients Manager plugin for WordPress version 2.0.6 and earlier, update to a version later than 2.0.6 to resolve the issue. As a temporary workaround, consider disabling the process actions function until a patch is available.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-10045

Affected Products

Transients Manager