The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
History

Wed, 04 Jun 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Gsplugins
Gsplugins logo Slider
Weaknesses CWE-352
CPEs cpe:2.3:a:gsplugins:logo_slider:*:*:*:*:*:wordpress:*:*
Vendors & Products Gsplugins
Gsplugins logo Slider

Sat, 17 May 2025 03:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Title GS Logo Slider < 3.7.1 - Settings Update via Cross-Site Request Forgery
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:07:20.142Z

Updated: 2025-05-17T02:59:19.467Z

Reserved: 2024-09-26T18:26:48.261Z

Link: CVE-2024-9233

cve-icon Vulnrichment

Updated: 2025-05-17T02:59:14.644Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:16:00.307

Modified: 2025-06-04T20:07:13.377

Link: CVE-2024-9233

cve-icon Redhat

No data.