CVE-2024-13146: Booknetic < 4.1.5 - Staff Creation via CSRF
The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13146?
CVE-2024-13146 is considered a medium severity vulnerability due to its potential for unauthorized staff account creation.
How do I fix CVE-2024-13146?
You can fix CVE-2024-13146 by updating the Booknetic WordPress plugin to version 4.1.5 or later.
What type of attack is possible with CVE-2024-13146?
CVE-2024-13146 allows attackers to conduct a Cross-Site Request Forgery (CSRF) attack to create arbitrary Staff accounts.
Who is affected by CVE-2024-13146?
CVE-2024-13146 affects users of the Booknetic WordPress plugin versions prior to 4.1.5.
What happens if CVE-2024-13146 is exploited?
If CVE-2024-13146 is exploited, an attacker could potentially create unauthorized staff accounts, compromising the site's security.