The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset the Nokaut Offers Box WordPress plugin through 1.4.0 via a CSRF attack
History

Mon, 09 Jun 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Nokautpl
Nokautpl nokaut Offers Box
Weaknesses CWE-352
CPEs cpe:2.3:a:nokautpl:nokaut_offers_box:*:*:*:*:*:wordpress:*:*
Vendors & Products Nokautpl
Nokautpl nokaut Offers Box

Tue, 20 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset the Nokaut Offers Box WordPress plugin through 1.4.0 via a CSRF attack
Title Nokaut Offers Box <= 1.4.0 - Plugin Reset via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:06:45.345Z

Updated: 2025-05-20T19:37:37.108Z

Reserved: 2024-10-31T18:17:51.909Z

Link: CVE-2024-10634

cve-icon Vulnrichment

Updated: 2025-05-19T20:37:49.275Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:33.543

Modified: 2025-06-09T18:09:43.180

Link: CVE-2024-10634

cve-icon Redhat

No data.