CVE-2024-4969
21.06.2024, 06:15
The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets, which could allow attackers to make logged in admin enable/disable widgets via a CSRF attack
Vendor | Product | Version |
---|---|---|
siteorigin | siteorigin_widgets_bundle | 𝑥 ≤ 2.0.0 |
devnath_verma | widget_bundle | 𝑥 ≤ 2.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration