Lucene search

K
nvd[email protected]NVD:CVE-2024-3971
HistoryJun 14, 2024 - 6:15 a.m.

CVE-2024-3971

2024-06-1406:15:12
CWE-352
web.nvd.nist.gov
9
similarity wordpress plugin
csrf vulnerability
admin reset
csrf attack

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

17.5%

The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack

Affected configurations

Nvd
Node
davidjmillersimilarityRange3.0wordpress
VendorProductVersionCPE
davidjmillersimilarity*cpe:2.3:a:davidjmiller:similarity:*:*:*:*:*:wordpress:*:*

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

17.5%