The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack
History

Tue, 06 May 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Xavi.ivars
Xavi.ivars xv Random Quotes
Weaknesses CWE-352
CPEs cpe:2.3:a:xavi.ivars:xv_random_quotes:*:*:*:*:*:wordpress:*:*
Vendors & Products Xavi.ivars
Xavi.ivars xv Random Quotes

Tue, 11 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 06:15:00 +0000

Type Values Removed Values Added
Description The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack
Title XV Random Quotes <= 1.40 - Settings Reset via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-03-11T06:00:08.551Z

Updated: 2025-03-11T14:43:42.684Z

Reserved: 2025-01-21T14:25:41.141Z

Link: CVE-2024-13580

cve-icon Vulnrichment

Updated: 2025-03-11T14:43:04.211Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-11T06:15:25.813

Modified: 2025-05-06T16:11:42.753

Link: CVE-2024-13580

cve-icon Redhat

No data.