CVE-2024-6860: WP MultiTasking <= 0.1.12 - Permalink Suffix Update via CSRF
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its permalink suffix settings, which could allow attackers to make logged admins perform such action via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6860?
CVE-2024-6860 has a moderate severity level due to its potential for CSRF attacks affecting logged-in administrators.
How do I fix CVE-2024-6860?
To fix CVE-2024-6860, update the WP MultiTasking plugin to the latest version that addresses the CSRF vulnerability.
What are the risks associated with CVE-2024-6860?
The risks associated with CVE-2024-6860 include unauthorized changes to permalink suffix settings by attackers exploiting CSRF vulnerabilities.
Which versions of WP MultiTasking are affected by CVE-2024-6860?
CVE-2024-6860 affects WP MultiTasking versions up to and including 0.1.12.
Is there a known exploit for CVE-2024-6860?
While specific exploits for CVE-2024-6860 are not detailed, the vulnerability allows for potential CSRF attacks against logged-in users.