First published: Mon Dec 16 2024(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Pearlbells Flash News / Post (Responsive), Pearlbells Post Title (TypeWriter) allows Privilege Escalation.This issue affects Flash News / Post (Responsive): from n/a through 4.1; Post Title (TypeWriter): from n/a through 4.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pearlbells Flash News / Post (Responsive) | >=n/a<=4.1 | |
Pearlbells Post Title | >=n/a<=4.1 | |
WordPress Post Title (TypeWriter) | <=4.1 | |
WordPress Flash News / Post (Responsive) | <=4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-56012 is a critical Cross-Site Request Forgery (CSRF) vulnerability that allows for privilege escalation.
CVE-2024-56012 can lead to unauthorized actions being performed by attackers on behalf of authenticated users.
To remediate CVE-2024-56012, update Pearlbells Flash News / Post (Responsive) or Pearlbells Post Title (TypeWriter) plugins to the latest versions beyond 4.1.
CVE-2024-56012 affects all versions of Pearlbells Flash News / Post (Responsive) and Pearlbells Post Title (TypeWriter) up to version 4.1.
CVE-2024-56012 requires an authenticated user session, making it potentially exploitable by attackers who can mimic legitimate user actions.