CVE-2024-7892: adstxt Plugin <= 1.0.0 - Settings Update via CSRF
The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7892?
CVE-2024-7892 is classified as a moderate severity vulnerability due to its potential for exploitation via CSRF attacks.
How do I fix CVE-2024-7892?
To fix CVE-2024-7892, update the adstxt WordPress plugin to version 1.0.1 or later, which includes CSRF protection enhancements.
What type of attack does CVE-2024-7892 facilitate?
CVE-2024-7892 facilitates Cross-Site Request Forgery (CSRF) attacks, allowing unauthorized changes by attacking a logged-in admin's session.
Which versions of the adstxt plugin are affected by CVE-2024-7892?
CVE-2024-7892 affects all versions of the adstxt plugin for WordPress up to and including version 1.0.0.
Can CVE-2024-7892 be exploited remotely?
Yes, CVE-2024-7892 can be exploited remotely if an attacker can trick a logged-in admin into performing certain actions.