6.1
CVE-2024-2857
- EPSS 0.34%
- Veröffentlicht 15.04.2024 05:15:15
- Zuletzt bearbeitet 08.05.2025 20:31:29
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Simple Buttons Creator <=1.04 - Unauthenticated Stored Cross-Site Scripting via Add Button
The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.
Mögliche Gegenmaßnahme
Simple Buttons Creator: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Simple Buttons Creator
Version
*-1.04
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Robbychen ≫ Simple Buttons Creator SwPlatformwordpress Version <= 1.04
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.561 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.