CVE-2024-7892

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Sep 25, 2024
Updated: Oct 7, 2024
CWE ID 352

Summary

CVE-2024-7892 is a vulnerability affecting the adstxt Plugin for WordPress. This issue permits attackers to manipulate plugin settings for administered sites through Cross-Site Request Forgery (CSRF) attacks. Since the plugin lacks a CSRF protection mechanism, an adversary can force a logged-in administrator to unwittingly modify plugin settings, potentially leading to serious consequences. This security flaw can be exploited without the need for valid authentication credentials or direct access to the web application.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share