Lucene search

K
cve[email protected]CVE-2024-3756
HistoryMay 06, 2024 - 6:15 a.m.

CVE-2024-3756

2024-05-0606:15:07
web.nvd.nist.gov
36
cve-2024-3756
wordpress
csrf
vulnerability
contributors
nvd

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%

The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack

Affected configurations

Vulners
Node
mf_gig_calendar_projectmf_gig_calendarRange1.2.1
VendorProductVersionCPE
mf_gig_calendar_projectmf_gig_calendar*cpe:2.3:a:mf_gig_calendar_project:mf_gig_calendar:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "MF Gig Calendar",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThanOrEqual": "1.2.1"
      }
    ],
    "defaultStatus": "affected"
  }
]

6.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.1%