nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-3481 CVE-2024-3481
MEDIUM
Counter Box < 1.2.4 - Counter Deletion via CSRF
Record summary
CVE-2024-3481 has a selected CVSS score of 5.2 (medium).
Description
The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 2, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Counter BoxDefault status: unaffected | CVE List | Before 1.2.4 | affected |
counter_boxBrowse wordpress / counter_boxDefault status: unknown | CVE List | - to < 1.2.4 | affected |
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/0c441293-e7f9-4634-8f3a-09925cd2b696