CVE-2024-6023

Severity
8.8HIGH
EPSS
0.2%
top 58.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12

Description

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5unknown/contentlock1.0.3

🔴Vulnerability Details

2
GHSA
GHSA-ppc6-pqcq-584g: The ContentLock WordPress plugin through 12024-07-12
CVEList
ContentLock <= 1.0.3 - Email Adding via CSRF2024-07-12
CVE-2024-6023 (HIGH CVSS 8.8) | The ContentLock WordPress plugin th | cvebase.io