CVE-2024-4344
Last modified
CVE-2024-4344 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.1.13. This is due to missing or incorrect nonce validation on the exec function. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.1.13. This is due to missing or incorrect nonce validation on the exec function. This makes it possible for unauthenticated attackers to disable pin protection for the admin interface of the plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-4344?
How severe is CVE-2024-4344?
How do I fix CVE-2024-4344?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-43434The bulk message sending feature in Moodle's Feedback module…8.1
- CVE-2024-43435A flaw was found in moodle. Insufficient capability checks m…5.3
- CVE-2024-43436A SQL injection risk flaw was found in the XMLDB editor tool…7.2
- CVE-2024-43437A flaw was found in moodle. Insufficient sanitizing of data …6.1
- CVE-2024-43438A flaw was found in Feedback. Bulk messaging in the activity…7.5
- CVE-2024-43439A flaw was found in moodle. H5P error messages require addit…6.1
- CVE-2024-43440A flaw was found in moodle. A local file may include risks w…7.5
- CVE-2024-43441Authentication Bypass by Assumed-Immutable Data vulnerabilit…9.8
- CVE-2024-43442Improper Neutralization of Input done by an attacker with ad…4.9
- CVE-2024-43443Improper Neutralization of Input done by an attacker with ad…4.9
- CVE-2024-43444Passwords of agents and customers are displayed in plain tex…8.2
- CVE-2024-43445A vulnerability exists in OTRS and ((OTRS Community Edition)…5.4
Are you affected by CVE-2024-4344?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
