CVE-2024-22140

Severity
8.8HIGH
EPSS
0.1%
top 73.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31

Description

Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5cozmoslabs/profile_builder_pron/a3.10.0

🔴Vulnerability Details

2
GHSA
GHSA-c2j8-9924-mr82: Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro2024-01-31
CVEList
WordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Cross Site Request Forgery (CSRF)2024-01-31
CVE-2024-22140 (HIGH CVSS 8.8) | Cross-Site Request Forgery (CSRF) v | cvebase.io