CVE-2024-6852: WP MultiTasking <= 0.1.12 - Settings Update via CSRF
Published Sep 8, 2024
·Updated
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected Software
1 affected component
Ngothang Wp Multitasking Wordpress<=0.1.12
Event History
Sep 8, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-6852?
CVE-2024-6852 has been rated as a medium severity vulnerability.
2
How does CVE-2024-6852 affect WordPress installations?
CVE-2024-6852 allows attackers to perform CSRF attacks on the WP MultiTasking plugin, affecting logged-in admin users.
3
What versions of the WP MultiTasking plugin are affected by CVE-2024-6852?
CVE-2024-6852 affects versions of the WP MultiTasking plugin up to and including 0.1.12.
4
How can I remediate CVE-2024-6852?
To fix CVE-2024-6852, update the WP MultiTasking plugin to a version that includes a CSRF check.
5
What should I do if I am unable to update due to CVE-2024-6852?
If you cannot update due to CVE-2024-6852, consider disabling the WP MultiTasking plugin until a patch is available.