Medium severity6.5NVD Advisory· Published Sep 12, 2024· Updated Jun 17, 2026
CVE-2024-7862
CVE-2024-7862
Description
The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=0.3.0+ 1 more
- (no CPE)range: <=0.3.0
- (no CPE)range: <=0.3.0
- cpe:2.3:a:kimhuebel:blogintroduction-wordpress-plugin:*:*:*:*:*:wordpress:*:*Range: <=0.3.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/9b54cd05-3bb8-4bb9-a0e4-fb00d97d5cae/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.