Record summary

CVE-2024-0379 has a selected CVSS score of 4.3 (medium); EIP currently links 1 repository PoC.

Description

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the ctf_auto_save_tokens function. This makes it possible for unauthenticated attackers to update the site's twitter API token and secret via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 8, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Browse smub / Custom Twitter Feeds – A Tweets Widget or X Feed Widget

Default status: unaffected

CVE ListThrough 2.2.1affected

Proofs of concept

1

Repository PoCs

GitHubkodaichodai/CVE-2024-0379Repository PoCby kodaichodaiStars: 0Not analyzed1 file

613 B

GitHub

PoC details

References

4