Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2024-3474
HistoryMay 02, 2024 - 6:00 a.m.

CVE-2024-3474 Wow Skype Buttons < 4.0.4 - Button Deletion via CSRF

2024-05-0206:00:02
WPScan
github.com
2
cve-2024-3474
csrf
wordpress_plugin

AI Score

7.1

Confidence

High

SSVC

Exploitation

none

Automatable

yes

Technical Impact

total

The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Wow Skype Buttons",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "4.0.4",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

7.1

Confidence

High

SSVC

Exploitation

none

Automatable

yes

Technical Impact

total

Related for VULNRICHMENT:CVE-2024-3474