First published: Sun Sep 08 2024(Updated: )
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=0.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6853 has a moderate severity rating due to its potential for causing unauthorized actions by logged-in administrators.
To mitigate CVE-2024-6853, update the WP MultiTasking WordPress plugin to a version that includes CSRF protection.
CVE-2024-6853 affects users of the WP MultiTasking plugin for WordPress version 0.1.12 and earlier.
CVE-2024-6853 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability.
Attackers can exploit CVE-2024-6853 to trick logged in administrators into updating welcome popups without their consent.