The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.
History

Mon, 09 Jun 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Joomlaserviceprovider
Joomlaserviceprovider jsp Store Locator
Weaknesses CWE-352
CPEs cpe:2.3:a:joomlaserviceprovider:jsp_store_locator:*:*:*:*:*:wordpress:*:*
Vendors & Products Joomlaserviceprovider
Joomlaserviceprovider jsp Store Locator

Tue, 20 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.
Title JSP Store Locator <= 1.0 - Deletion via Missing CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:06:52.758Z

Updated: 2025-05-20T19:33:00.155Z

Reserved: 2024-12-06T13:50:35.524Z

Link: CVE-2024-12301

cve-icon Vulnrichment

Updated: 2025-05-19T20:34:48.969Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:35.837

Modified: 2025-06-09T18:42:17.283

Link: CVE-2024-12301

cve-icon Redhat

No data.