The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
History

Mon, 09 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Floriansimunek
Floriansimunek connexion Logs
Weaknesses CWE-352
CPEs cpe:2.3:a:floriansimunek:connexion_logs:*:*:*:*:*:wordpress:*:*
Vendors & Products Floriansimunek
Floriansimunek connexion Logs

Tue, 20 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Title Connexion Logs <= 3.0.2 - Log Deletion via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:06:49.998Z

Updated: 2025-05-20T19:34:16.694Z

Reserved: 2024-11-18T19:30:50.522Z

Link: CVE-2024-11373

cve-icon Vulnrichment

Updated: 2025-05-19T20:35:47.698Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:35.193

Modified: 2025-06-09T18:51:30.493

Link: CVE-2024-11373

cve-icon Redhat

No data.