CVE-2024-8476: Easy PayPal Events <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Post Deletion
The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the wpeeventpluginbuttons() function. This makes it possible for unauthenticated attackers to delete arbitrary posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8476?
CVE-2024-8476 is classified as a medium severity vulnerability due to its potential for Cross-Site Request Forgery.
How do I fix CVE-2024-8476?
To fix CVE-2024-8476, update the Easy PayPal Events plugin to version 1.2.2 or later, ensuring proper nonce validation.
Who is impacted by CVE-2024-8476?
All users of the Easy PayPal Events plugin for WordPress versions up to and including 1.2.1 are impacted by CVE-2024-8476.
What type of vulnerability is CVE-2024-8476?
CVE-2024-8476 is a Cross-Site Request Forgery vulnerability due to missing proper nonce validation.
Can unauthenticated attackers exploit CVE-2024-8476?
Yes, unauthenticated attackers can exploit CVE-2024-8476 to perform unauthorized actions on behalf of users.