Lucene search

K
cvePatchstackCVE-2024-31922
HistoryApr 15, 2024 - 10:15 a.m.

CVE-2024-31922

2024-04-1510:15:11
CWE-352
Patchstack
web.nvd.nist.gov
28
cve-2024-31922
cross-site request forgery
anton aleksandrov
wordpress hosting benchmark tool
nvd

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

6.8

Confidence

Low

EPSS

0

Percentile

9.0%

Cross-Site Request Forgery (CSRF) vulnerability in Anton Aleksandrov WordPress Hosting Benchmark tool.This issue affects WordPress Hosting Benchmark tool: from n/a through 1.3.6.

Affected configurations

Vulners
Node
anton_aleksandrovwordpress_hosting_benchmark_toolRange1.3.6wordpress
VendorProductVersionCPE
anton_aleksandrovwordpress_hosting_benchmark_tool*cpe:2.3:a:anton_aleksandrov:wordpress_hosting_benchmark_tool:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "wpbenchmark",
    "product": "WordPress Hosting Benchmark tool",
    "vendor": "Anton Aleksandrov",
    "versions": [
      {
        "changes": [
          {
            "at": "1.3.7",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "1.3.6",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

6.8

Confidence

Low

EPSS

0

Percentile

9.0%