CVE-2024-10045: Transients Manager <= 2.0.6 - Cross-Site Request Forgery
The Transients Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing or incorrect nonce validation on the processactions function. This makes it possible for unauthenticated attackers to delete transients via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10045?
CVE-2024-10045 is rated as a critical severity vulnerability due to its potential for unauthenticated access and deletion of transients.
How do I fix CVE-2024-10045?
To fix CVE-2024-10045, update the Transients Manager plugin to version 2.0.7 or later.
What type of vulnerability is CVE-2024-10045?
CVE-2024-10045 is a Cross-Site Request Forgery (CSRF) vulnerability.
Who is affected by CVE-2024-10045?
All users of the Transients Manager plugin for WordPress, specifically versions up to and including 2.0.6, are affected by CVE-2024-10045.
What does CVE-2024-10045 allow an attacker to do?
CVE-2024-10045 allows unauthenticated attackers to delete transients, potentially disrupting site functionality.