CVE-2024-3481
Last modified
CVE-2024-3481 is a medium-severity vulnerability rated 5.2/10 on the CVSS scale. The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such deleting counters via CSRF attacks
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wow-Company | Counter Box | < 1.2.4 |
References
- https://wpscan.com/vulnerability/0c441293-e7f9-4634-8f3a-09925cd2b696/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/0c441293-e7f9-4634-8f3a-09925cd2b696/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-3481?
How severe is CVE-2024-3481?
How do I fix CVE-2024-3481?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-34804Missing Authorization vulnerability in Tagembed.This issue a…5.4
- CVE-2024-34805Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2024-34806Cross-Site Request Forgery (CSRF) vulnerability in Creative …4.3
- CVE-2024-34807Cross-Site Request Forgery (CSRF) vulnerability in CodeBard …4.3
- CVE-2024-34808Improper Limitation of a Pathname to a Restricted Directory …4.3
- CVE-2024-34809Cross-Site Request Forgery (CSRF) vulnerability in Extend Th…4.3
- CVE-2024-34810Cross-Site request forgery (CSRF) vulnerability in Extend Th…4.3
- CVE-2024-34811Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2024-34812Insertion of Sensitive Information Into Sent Data vulnerabil…5.3
- CVE-2024-34813Missing Authorization vulnerability in Moreconvert Team MC W…5.3
- CVE-2024-34814Cross-Site Request Forgery (CSRF) vulnerability in Unyson Un…5.4
- CVE-2024-34815Missing Authorization vulnerability in Javier Carazo Import …5.4
Are you affected by CVE-2024-3481?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
