PT-2024-27658 · WordPress · Mf Gig Calendar

Bob Matyas

·

Published

2024-05-06

·

Updated

2024-07-18

·

CVE-2024-3756

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MF Gig Calendar WordPress plugin versions 1.2.1 and earlier
Description The issue is related to the lack of CSRF checks in some places, which could allow attackers to make logged-in Contributors and above delete arbitrary events via a CSRF attack. This could potentially affect a significant number of devices worldwide, although the exact number is not specified. There is no information provided about real-world incidents where this issue was exploited.
Recommendations For MF Gig Calendar WordPress plugin versions 1.2.1 and earlier, update to a version that includes CSRF checks to prevent such attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

BIT-WORDPRESS-2024-3756
BIT-WORDPRESS-MULTISITE-2024-3756
CVE-2024-3756

Affected Products

Mf Gig Calendar