The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
Metrics
Affected Vendors & Products
References
History
Thu, 08 May 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Marvinlabs
Marvinlabs wp Customer Area |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:marvinlabs:wp_customer_area:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Marvinlabs
Marvinlabs wp Customer Area |
Mon, 27 Jan 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 27 Jan 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks | |
Title | WP Customer Area <= 8.2.4 - Bulk Delete via CSRF | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-01-27T06:00:06.330Z
Updated: 2025-01-27T20:06:08.471Z
Reserved: 2024-12-10T18:23:32.234Z
Link: CVE-2024-12436

Updated: 2025-01-27T20:06:03.182Z

Status : Analyzed
Published: 2025-01-27T06:15:22.623
Modified: 2025-05-08T18:42:45.450
Link: CVE-2024-12436

No data.