CVE-2024-3475: Sticky Buttons < 3.2.4 - Button Deletion via CSRF
The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3475?
CVE-2024-3475 is rated as a medium severity vulnerability due to its potential to allow unauthorized actions by logged-in admins.
How do I fix CVE-2024-3475?
To mitigate CVE-2024-3475, upgrade the Sticky Buttons WordPress plugin to version 3.2.4 or later.
What exploitation methods are associated with CVE-2024-3475?
CVE-2024-3475 can be exploited through Cross-Site Request Forgery (CSRF) attacks that target bulk actions performed by logged-in administrators.
Who is affected by CVE-2024-3475?
CVE-2024-3475 affects installations of the Sticky Buttons WordPress plugin prior to version 3.2.4.
What are the consequences of CVE-2024-3475?
The consequences of CVE-2024-3475 may include unauthorized button deletions and other harmful actions carried out by attackers impersonating admins.