CVE-2024-1446: NextScripts: Social Networks Auto-Poster <= 4.4.3 - Cross-Site Request Forgery to Arbitrary Post Deletion
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.3. This is due to missing or incorrect nonce validation on the nxssnap-reposter page. This makes it possible for unauthenticated attackers to delete arbitrary posts or pages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1446?
CVE-2024-1446 is classified as a medium severity vulnerability due to its potential for exploitation in Cross-Site Request Forgery attacks.
How do I fix CVE-2024-1446?
To fix CVE-2024-1446, update the NextScripts: Social Networks Auto-Poster plugin to version 4.4.4 or higher.
Who is affected by CVE-2024-1446?
CVE-2024-1446 affects all versions of the NextScripts: Social Networks Auto-Poster plugin up to and including version 4.4.3.
What type of vulnerability is CVE-2024-1446?
CVE-2024-1446 is a Cross-Site Request Forgery (CSRF) vulnerability caused by inadequate nonce validation.
Can unauthenticated users exploit CVE-2024-1446?
Yes, unauthenticated users can exploit CVE-2024-1446 due to missing nonce validation on the nxssnap-reposter page.