THREATOPS
THREAT OPSThreat News › [NVD] CVE-2024-3823 (LOW 2.4) — The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

[NVD] CVE-2024-3823 (LOW 2.4) — The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

lownvdPublished 2024-05-15

CVE-2024-3823 CVSS: 2.4 LOW Published: 2024-05-15T06:15:14.650

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-3823