The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
History

Thu, 12 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Justintadlock
Justintadlock widgets Reset
Weaknesses CWE-352
CPEs cpe:2.3:a:justintadlock:widgets_reset:*:*:*:*:*:wordpress:*:*
Vendors & Products Justintadlock
Justintadlock widgets Reset

Tue, 20 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Title Widgets Reset <= 0.1 - Settings Update via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:07:13.191Z

Updated: 2025-05-20T19:20:35.183Z

Reserved: 2024-08-22T12:30:29.856Z

Link: CVE-2024-8082

cve-icon Vulnrichment

Updated: 2025-05-19T20:25:10.693Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:57.590

Modified: 2025-06-12T16:53:49.273

Link: CVE-2024-8082

cve-icon Redhat

No data.