CVE-2024-0592

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 13, 2024

Summary

CVE-2024-0592: The Related Posts plugin for WordPress, used in versions up to and including 2.2.1, is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This issue stems from the lack of proper nonce validation in the handle_create_link() function. As a consequence, unauthenticated attackers can manipulate other users into executing a malicious request, enabling them to add related posts to targeted posts. Ultimately, this vulnerability grants attackers access to view draft and password-protected posts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share