CVE-2024-0790: WOLF – WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Cross-Site Request Forgery
The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8.1. This is due to missing or incorrect nonce validation on the wpbecreatenewterm, wpbeupdatetaxterm, and wpbedeletetaxterm functions. This makes it possible for unauthenticated attackers to create, modify and delete taxonomy terms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Furthermore, the functions wpbesaveoptions, wpbebulkdeletepostscount, wpbebulkdeleteposts, and wpbesavemeta are vulnerable to Cross-Site Request Forgery allowing for plugin options update, post count deletion, post deletion and modification of post metadata via forged request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0790?
CVE-2024-0790 is classified as a moderate severity vulnerability due to its potential for Cross-Site Request Forgery.
How do I fix CVE-2024-0790?
To fix CVE-2024-0790, update the WOLF – WordPress Posts Bulk Editor and Manager Professional plugin to version 1.0.8.2 or later.
What type of vulnerability is CVE-2024-0790?
CVE-2024-0790 is a Cross-Site Request Forgery (CSRF) vulnerability affecting WordPress.
Which versions are affected by CVE-2024-0790?
All versions of the WOLF – WordPress Posts Bulk Editor and Manager Professional plugin up to and including 1.0.8.1 are affected by CVE-2024-0790.
Who is affected by CVE-2024-0790?
Users of the WOLF – WordPress Posts Bulk Editor and Manager Professional plugin prior to version 1.0.8.2 are at risk due to CVE-2024-0790.