Lucene search

K
cveWPScanCVE-2024-3965
HistoryJun 14, 2024 - 6:15 a.m.

CVE-2024-3965

2024-06-1406:15:12
WPScan
web.nvd.nist.gov
24
pray for me
wordpress
csrf
vulnerability
update settings
csrf attack
admin

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.0%

The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

Affected configurations

Vulners
Vulnrichment
Node
projectcarusopray_for_meRange1.0.4wordpress
VendorProductVersionCPE
projectcarusopray_for_me*cpe:2.3:a:projectcaruso:pray_for_me:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Pray For Me",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThanOrEqual": "1.0.4"
      }
    ],
    "defaultStatus": "affected"
  }
]

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

AI Score

6.4

Confidence

High

EPSS

0

Percentile

9.0%