CVE-2024-6856: WP MultiTasking <= 0.1.12 - SMTP Settings Update via CSRF
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6856?
CVE-2024-6856 has been rated as a medium severity vulnerability due to its potential for CSRF attacks against an admin.
How do I fix CVE-2024-6856?
To fix CVE-2024-6856, upgrade the WP MultiTasking plugin to a version later than 0.1.12 where CSRF checks are implemented.
What systems are affected by CVE-2024-6856?
CVE-2024-6856 affects the WP MultiTasking plugin for WordPress versions up to and including 0.1.12.
Who can exploit CVE-2024-6856?
An attacker with access to a logged-in admin session can exploit CVE-2024-6856 through a CSRF attack.
What is a CSRF attack in relation to CVE-2024-6856?
A CSRF attack in the context of CVE-2024-6856 allows unauthorized changes to settings by tricking an admin into submitting a malicious request.