Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2024-3471
HistoryMay 02, 2024 - 6:00 a.m.

CVE-2024-3471 Button Generator < 3.0 - Button Deletion via CSRF

2024-05-0206:00:02
WPScan
github.com
1
wordpress
plugin
csrf
vulnerability
attackers
admin

AI Score

7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Button Generator ",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "3.0",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

7

Confidence

Low

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-3471