The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks
Metrics
Affected Vendors & Products
References
History
Tue, 25 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 21 Mar 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wow-company
Wow-company wow Skype Buttons |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:wow-company:wow_skype_buttons:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wow-company
Wow-company wow Skype Buttons |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-25T13:21:57.506Z
Reserved: 2024-04-08T18:29:39.922Z
Link: CVE-2024-3474

Updated: 2024-08-01T20:12:07.276Z

Status : Modified
Published: 2024-05-02T06:15:50.527
Modified: 2025-03-25T14:15:25.040
Link: CVE-2024-3474

No data.