CVE-2024-3631
MEDIUMHL Twitter WordPress Plugin <= 2014.1.18 - Cross-Site Request Forgery via Twitter Account Unlinking
Title source: llmDescription
The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins perform such actions via a CSRF attack
References (1)
Core 1
Core References
Exploit, Third Party Advisory exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/c59a8b49-6f3e-452b-ba9b-50b80c522ee9/
Scores
CVSS v3
4.3
EPSS
0.0021
EPSS Percentile
11.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-352
Status
published
Products (1)
dachande663/hl_twitter
< 2014.1.18
Published
May 15, 2024
Tracked Since
Feb 18, 2026