PT-2024-17268 · WordPress · Seopilot Dla Wp

Soprobro

·

Published

2024-12-20

·

Updated

2024-12-20

·

CVE-2024-11812

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wtyczka SeoPilot dla WP plugin for WordPress versions up to, and including, 3.3.091
Description The issue is related to Cross-Site Request Forgery due to missing or incorrect nonce validation on the SeoPilot Admin Options() function. This allows unauthenticated attackers to update settings and inject malicious web scripts via a forged request, provided they can trick a site administrator into performing an action such as clicking on a link.
Recommendations For versions up to, and including, 3.3.091, consider disabling the SeoPilot Admin Options() function until a patch is available to prevent exploitation. Restrict access to administrative options to minimize the risk of settings updates by unauthorized parties. Avoid performing actions that could be triggered by forged requests, such as clicking on suspicious links, to reduce the risk of malicious script injection.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-11812

Affected Products

Seopilot Dla Wp