CVE-2024-39680
MEDIUMCooked < 1.8.0 - Cross-Site Request Forgery via AJAX Action Handler
Title source: llmDescription
Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they didn't intend to perform under their current authentication. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
References (1)
Core 1
Core References
Exploit, Vendor Advisory x_refsource_confirm
https://github.com/XjSv/Cooked/security/advisories/GHSA-f2mc-hcp9-6xgr
Scores
CVSS v3
5.4
EPSS
0.0033
EPSS Percentile
25.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-352
Status
published
Products (1)
boxystudio/cooked
< 1.8.0
Published
Jul 18, 2024
Tracked Since
Feb 18, 2026