Lucene search

K
cvelistWPScanCVELIST:CVE-2024-2376
HistoryJul 03, 2024 - 6:00 a.m.

CVE-2024-2376 WPQA < 6.1.1 - Arbitrary Category and Tag Follow/Unfollow via CSRF

2024-07-0306:00:04
WPScan
www.cve.org
6
cve-2024-2376
wpqa builder
csrf
wordpress plugin

EPSS

0.001

Percentile

24.3%

The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "WPQA Builder",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThan": "6.1.1"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

EPSS

0.001

Percentile

24.3%

Related for CVELIST:CVE-2024-2376