PT-2024-28617 · WordPress · Cooked

Iamr3N0

+1

·

Published

2024-07-17

·

Updated

2025-02-10

·

CVE-2024-39678

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cooked versions up to, and including, 1.7.15.4
Description The Cooked plugin for WordPress is affected by a Cross-Site Request Forgery (CSRF) issue due to missing or incorrect nonce validation on the AJAX action handler. This could allow an attacker to trick users into performing unintended actions under their current authentication.
Recommendations For versions up to, and including, 1.7.15.4, upgrade to release version 1.8.0 to address the issue. As a temporary workaround, consider restricting access to the AJAX action handler until the upgrade is applied.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-39678
GHSA-PP3H-GHXF-R9PC

Affected Products

Cooked