CVE-2024-7892
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Sep 25, 2024
Updated: Oct 7, 2024
CWE ID 352
Summary
CVE-2024-7892 is a vulnerability affecting the adstxt Plugin for WordPress. This issue permits attackers to manipulate plugin settings for administered sites through Cross-Site Request Forgery (CSRF) attacks. Since the plugin lacks a CSRF protection mechanism, an adversary can force a logged-in administrator to unwittingly modify plugin settings, potentially leading to serious consequences. This security flaw can be exploited without the need for valid authentication credentials or direct access to the web application.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.