CVE-2024-2739: Advance Search <= 1.1.6 - Shortcode Deletion via CSRF
The Advanced Search WordPress plugin through 1.1.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2739?
CVE-2024-2739 has a medium severity level due to the lack of CSRF checks that could allow attackers to exploit the vulnerability.
How do I fix CVE-2024-2739?
To fix CVE-2024-2739, update the Advanced Search WordPress plugin to version 1.1.7 or higher where the CSRF checks are implemented.
What types of actions could attackers perform using CVE-2024-2739?
Attackers could use CVE-2024-2739 to make logged-in users perform unwanted actions on the affected WordPress site.
Which versions of the Advanced Search plugin are affected by CVE-2024-2739?
Versions of the Advanced Search plugin prior to 1.1.7, specifically up to and including 1.1.6, are affected by CVE-2024-2739.
Who is impacted by CVE-2024-2739?
Anyone using the Advanced Search WordPress plugin version 1.1.6 or earlier is potentially impacted by CVE-2024-2739.