CVE-2024-6751: Social Auto Poster <= 5.3.14 - Cross-Site Request Forgery via Multiple Functions
The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated attackers to add, modify, or delete post meta and plugin options.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6751?
The severity of CVE-2024-6751 is considered high due to the potential impact of Cross-Site Request Forgery attacks.
How do I fix CVE-2024-6751?
To fix CVE-2024-6751, update the Social Auto Poster plugin to version 5.3.15 or later.
Who is affected by CVE-2024-6751?
Users of the Social Auto Poster plugin for WordPress versions up to and including 5.3.14 are affected by CVE-2024-6751.
What types of attacks are possible with CVE-2024-6751?
CVE-2024-6751 allows unauthenticated attackers to add, modify, or delete posts using Cross-Site Request Forgery.
Is authentication required to exploit CVE-2024-6751?
No, authentication is not required to exploit CVE-2024-6751, making it particularly risky.