CVE-2024-12634: Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.59 - Cross-Site Request Forgery to Stored Cross-Site Scripting
The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 2.0.59. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12634?
CVE-2024-12634 has been classified as a medium severity vulnerability due to its ability to enable Cross-Site Request Forgery attacks.
How do I fix CVE-2024-12634?
To fix CVE-2024-12634, update the PickPlugins Related Posts, Inline Related Posts, Contextual Related Posts, Related Content plugin to version 2.0.60 or later, which includes the necessary nonce validation.
What versions are affected by CVE-2024-12634?
CVE-2024-12634 affects all versions of the PickPlugins Related Posts plugin up to and including version 2.0.59.
What type of attack is associated with CVE-2024-12634?
CVE-2024-12634 is associated with Cross-Site Request Forgery (CSRF) attacks due to missing nonce validation.
Who is affected by CVE-2024-12634?
Users of the PickPlugins Related Posts, Inline Related Posts, Contextual Related Posts, and Related Content plugin for WordPress are affected by CVE-2024-12634.