The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
History

Thu, 12 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Philipwalton
Philipwalton simple Nav Archives
Weaknesses CWE-352
CPEs cpe:2.3:a:philipwalton:simple_nav_archives:*:*:*:*:*:wordpress:*:*
Vendors & Products Philipwalton
Philipwalton simple Nav Archives

Sat, 17 May 2025 04:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Title Simple Nav Archives <= 2.1.3 - Settings Update via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:07:15.365Z

Updated: 2025-05-17T03:16:02.348Z

Reserved: 2024-09-03T17:45:50.336Z

Link: CVE-2024-8398

cve-icon Vulnrichment

Updated: 2025-05-17T03:15:57.466Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:58.583

Modified: 2025-06-12T15:43:26.017

Link: CVE-2024-8398

cve-icon Redhat

No data.