PT-2024-28620 · WordPress · Cooked

Iamr3N0

+1

·

Published

2024-07-17

·

Updated

2025-02-10

·

CVE-2024-39680

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cooked plugin for WordPress versions up to, and including, 1.7.15.4
Description The issue is related to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the AJAX action handler. This could allow an attacker to trick users into performing unintended actions under their current authentication. The problem has been addressed in release version 1.8.0.
Recommendations For versions up to, and including, 1.7.15.4, upgrade to release version 1.8.0 to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action handler until the upgrade is applied.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-39680
GHSA-F2MC-HCP9-6XGR

Affected Products

Cooked