The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, such as delete arbitrary subscribers
Metrics
Affected Vendors & Products
References
History
Wed, 14 May 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Themeqx
Themeqx letterpress |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:themeqx:letterpress:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Themeqx
Themeqx letterpress |
Wed, 21 Aug 2024 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-05-09T06:00:02.736Z
Updated: 2024-08-21T20:51:24.611Z
Reserved: 2024-04-10T14:34:26.500Z
Link: CVE-2024-3590

Updated: 2024-08-01T20:12:07.919Z

Status : Analyzed
Published: 2024-05-14T15:41:54.880
Modified: 2025-05-14T17:00:15.867
Link: CVE-2024-3590

No data.