CVE-2024-13521: MailUp Auto Subscription <= 1.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the masoptions function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13521?
CVE-2024-13521 has been classified as a medium severity vulnerability due to the potential for unauthorized access and data manipulation.
How do I fix CVE-2024-13521?
To fix CVE-2024-13521, update the MailUp Auto Subscription plugin to version 1.2.0 or later, which includes the necessary nonce validation.
What type of vulnerability is CVE-2024-13521?
CVE-2024-13521 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
Who is affected by CVE-2024-13521?
CVE-2024-13521 affects all versions of the MailUp Auto Subscription plugin for WordPress up to and including version 1.1.0.
Can unauthenticated attackers exploit CVE-2024-13521?
Yes, unauthenticated attackers can exploit CVE-2024-13521 due to the missing or incorrect nonce validation in the plugin.