CVE-2024-0592: Related Posts for WordPress <= 2.2.1 - Cross-Site Request Forgery
The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the handlecreatelink() function. This makes it possible for unauthenticated attackers to add related posts to other posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This ultimately makes it possible for attackers to view draft and password protected posts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0592?
CVE-2024-0592 is classified as a moderate severity vulnerability due to its potential to allow unauthorized actions.
How do I fix CVE-2024-0592?
The fix for CVE-2024-0592 is to update the Related Posts for WordPress plugin to version 2.2.2 or later.
What type of vulnerability is CVE-2024-0592?
CVE-2024-0592 is a Cross-Site Request Forgery vulnerability affecting the Related Posts for WordPress plugin.
Who is affected by CVE-2024-0592?
Any user of the Related Posts for WordPress plugin version 2.2.1 or earlier is affected by CVE-2024-0592.
Can CVE-2024-0592 be exploited by authenticated users?
CVE-2024-0592 can be exploited by unauthenticated users, making it a significant concern for site security.