6.8
CVE-2024-5284
- EPSS 0.24%
- Veröffentlicht 13.07.2024 06:15:04
- Zuletzt bearbeitet 19.05.2025 14:59:16
- CVE-Watchlists
- Unerledigt
WP Affiliate Platform < 6.5.1 - Stored XSS via CSRF
WP Affiliate Platform < 6.5.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Mögliche Gegenmaßnahme
WP Affiliate Platform: Update to version 6.5.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tipsandtricks-hq ≫ Wp Affiliate Platform SwPlatformwordpress Version < 6.5.1
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WP Affiliate Platform
Version
[*, 6.5.1)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.149 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.8 | 2.1 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
https://wpscan.com/vulnerability/a601a267-e781-439f-9c76-b4c841e819e5/
https://www.wordfence.com/threat-intel/vulnerabilities/id/ff210859-a65f-494f-a2bd-36b7ff92dec0