PT-2024-3158 · WordPress · Wp Automatic

Rafie Muhammad

·

Published

2024-02-25

·

Updated

2024-05-17

·

CVE-2024-27955

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WP Automatic versions 3.92.0 and earlier
Description The issue is related to a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to Privilege Escalation. This vulnerability is due to incorrect validation of the nonce value, allowing a remote attacker to exploit it and gain elevated privileges.
Recommendations For versions 3.92.0 and earlier, update to a version later than 3.92.0 to resolve the issue. As a temporary workaround, consider implementing additional validation for the nonce value to prevent CSRF attacks. Restrict access to sensitive areas of the WP Automatic plugin to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

BDU:2024-03371
CVE-2024-27955

Affected Products

Wp Automatic