First published: Fri Jul 12 2024(Updated: )
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in admin perform such action via a CSRF attack
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6023 is considered a critical vulnerability due to the potential for CSRF attacks that can compromise the actions of an admin user.
To fix CVE-2024-6023, update the ContentLock WordPress plugin to version 1.0.4 or higher.
CVE-2024-6023 affects all versions of the ContentLock WordPress plugin up to and including 1.0.3.
CVE-2024-6023 is a Cross-Site Request Forgery (CSRF) vulnerability.
Yes, CVE-2024-6023 can be exploited remotely by an attacker who targets a logged-in admin of a WordPress site using the affected plugin.