ZeroHour

CVE-2024-9689

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p11
Published
()
Modified
Description

The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin perform such action via a CSRF attack

Vendors
shaon
Products
post from frontend
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.