CVE-2024-6853: WP MultiTasking <= 0.1.12 - Welcome Popup Update via CSRF
Published Sep 8, 2024
·Updated
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack
Affected Software
1 affected component
Ngothang Wp Multitasking Wordpress<=0.1.12
Event History
Sep 8, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-6853?
CVE-2024-6853 has a moderate severity rating due to its potential for causing unauthorized actions by logged-in administrators.
2
How can I mitigate CVE-2024-6853?
To mitigate CVE-2024-6853, update the WP MultiTasking WordPress plugin to a version that includes CSRF protection.
3
Who is affected by CVE-2024-6853?
CVE-2024-6853 affects users of the WP MultiTasking plugin for WordPress version 0.1.12 and earlier.
4
What type of vulnerability is CVE-2024-6853?
CVE-2024-6853 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability.
5
What actions can attackers perform due to CVE-2024-6853?
Attackers can exploit CVE-2024-6853 to trick logged in administrators into updating welcome popups without their consent.