CVE-2024-8200: Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 - Cross-Site Request Forgery
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'updateapikey' function. This makes it possible for unauthenticated attackers to update an API key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8200?
CVE-2024-8200 has been classified as a moderate severity vulnerability due to its potential for exploitation through Cross-Site Request Forgery.
How do I fix CVE-2024-8200?
To fix CVE-2024-8200, upgrade the Reviews Feed plugin for WordPress to version 1.2.0 or later which includes improved nonce validation.
What software versions are affected by CVE-2024-8200?
CVE-2024-8200 affects all versions of the Reviews Feed plugin for WordPress up to and including version 1.1.2.
What type of vulnerability is CVE-2024-8200?
CVE-2024-8200 is a Cross-Site Request Forgery vulnerability that allows attackers to perform actions on behalf of an authenticated user.
Who is the vendor for the product affected by CVE-2024-8200?
The vendor for the product affected by CVE-2024-8200 is Smashballoon, which develops the Reviews Feed plugin for WordPress.