CVE-2024-8157: Alphabetical List <= 1.0.3 - Settings Update via CSRF
The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8157?
CVE-2024-8157 is considered a medium severity vulnerability due to the potential for unauthorized changes by attackers.
How do I fix CVE-2024-8157?
To fix CVE-2024-8157, update the Alphabetical List WordPress plugin to a version higher than 1.0.3 where the CSRF checks have been implemented.
Who is affected by CVE-2024-8157?
CVE-2024-8157 affects all versions of the Alphabetical List WordPress plugin up to and including 1.0.3.
What type of attack does CVE-2024-8157 allow?
CVE-2024-8157 allows for a CSRF (Cross-Site Request Forgery) attack that can lead to unauthorized changes in the plugin's settings by an attacker.
Is there a recommended action for users of the Alphabetical List plugin regarding CVE-2024-8157?
Users of the Alphabetical List plugin should immediately update to a secure version to mitigate the risk associated with CVE-2024-8157.