The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating its Header, Footer and Body Script Settings, which could allow attackers to make logged admins perform such action via a CSRF attack
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/97636602-2dd0-465b-b6dc-acb42147edb3/ | Exploit Third Party Advisory |
Configurations
History
22 Apr 2025, 17:25
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/97636602-2dd0-465b-b6dc-acb42147edb3/ - Exploit, Third Party Advisory | |
First Time |
Ngothang
Ngothang wp Multitasking |
|
CPE | cpe:2.3:a:ngothang:wp_multitasking:*:*:*:*:*:wordpress:*:* | |
CWE | CWE-352 |
09 Apr 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
09 Apr 2025, 20:02
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
09 Apr 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-09 06:15
Updated : 2025-04-22 17:25
NVD link : CVE-2024-6857
Mitre link : CVE-2024-6857
CVE.ORG link : CVE-2024-6857
JSON object : View
Products Affected
ngothang
- wp_multitasking
CWE
CWE-352
Cross-Site Request Forgery (CSRF)