CVE-2024-38344

medium

Description

A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is exploited, an attacker allows a user who logs in to the WordPress site where the affected plugin is enabled to access a malicious page. As a result, the user may perform unintended operations on the WordPress site.

References

https://wordpress.org/plugins/wp-tweet-walls/

https://jvn.jp/en/jp/JVN34977158/

Details

Source: Mitre, NVD

Published: 2024-07-04

Updated: 2024-12-06

Risk Information

CVSS v2

Base Score: 5.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Severity: Medium

EPSS

EPSS: 0.00084