6.8
CVE-2024-5284
- EPSS 0.09%
- Veröffentlicht 13.07.2024 06:15:04
- Zuletzt bearbeitet 19.05.2025 14:59:16
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
WP Affiliate Platform < 6.5.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Mögliche Gegenmaßnahme
WP Affiliate Platform: Update to version 6.5.1, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WP Affiliate Platform
Version
[*, 6.5.1)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tipsandtricks-hq ≫ Wp Affiliate Platform SwPlatformwordpress Version < 6.5.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.25 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.8 | 2.1 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.