CVE-2024-4382

June 21, 2024, 11:22 a.m.

Undergoing Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

CB WordPress plugin

  • 0.9.4.18 and below

Source

contact@wpscan.com

Tags

CVE-2024-4382 details

Published : June 21, 2024, 6:15 a.m.
Last Modified : June 21, 2024, 11:22 a.m.

Description

The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
This website uses the NVD API, but is not approved or certified by it.