First published: Wed Mar 13 2024(Updated: )
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.0.1. This is due to missing or incorrect nonce validation on the 'posting_bulk' function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
HPE OneView Global Dashboard | <=4.6.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1642 is classified as a medium severity vulnerability due to its Cross-Site Request Forgery risk.
To fix CVE-2024-1642, update the MainWP Dashboard plugin to version 4.6.0.2 or later.
CVE-2024-1642 is caused by missing or incorrect nonce validation in the 'posting_bulk' function.
All versions of the MainWP Dashboard plugin up to and including 4.6.0.1 are affected by CVE-2024-1642.
The potential impact of CVE-2024-1642 includes unauthorized actions being performed on behalf of authenticated users due to Cross-Site Request Forgery.