PT-2024-24167 · WordPress · Easy Property Listings

Bob Matyas

·

Published

2024-09-11

·

Updated

2024-09-26

·

CVE-2024-3163

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Easy Property Listings WordPress plugin versions prior to 3.5.4
Description The issue is related to a lack of CSRF check when deleting contacts in bulk, which could allow attackers to make a logged-in admin delete them via a CSRF attack. This could potentially lead to malicious actions.
Recommendations For versions prior to 3.5.4, upgrade the Easy Property Listings WordPress plugin to version 3.5.4 or later to mitigate the risk of CSRF attacks. As a temporary workaround, consider restricting access to the bulk contact deletion feature until the plugin is updated.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-3163

Affected Products

Easy Property Listings