PT-2024-33583 · Unknown · Whiletrue Most/Least Read Posts Widget

Soprobro

·

Published

2024-10-20

·

Updated

2024-10-22

·

CVE-2024-49628

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WhileTrue Most And Least Read Posts Widget versions 2.5.18 and earlier
Description A Cross-Site Request Forgery (CSRF) issue exists in the WhileTrue Most And Least Read Posts Widget. This allows for Cross Site Request Forgery.
Recommendations For versions 2.5.18 and earlier, update to a version later than 2.5.18 to resolve the issue. As a temporary workaround, consider implementing CSRF token validation to prevent unauthorized requests. Restrict access to sensitive functionality to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-49628

Affected Products

Whiletrue Most/Least Read Posts Widget