CVE-2024-0592
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Mar 13, 2024
Summary
CVE-2024-0592: The Related Posts plugin for WordPress, used in versions up to and including 2.2.1, is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This issue stems from the lack of proper nonce validation in the handle_create_link() function. As a consequence, unauthenticated attackers can manipulate other users into executing a malicious request, enabling them to add related posts to targeted posts. Ultimately, this vulnerability grants attackers access to view draft and password-protected posts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share