Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8106 | The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack |
Wed, 30 Apr 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fs-code
Fs-code booknetic |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:fs-code:booknetic:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Fs-code
Fs-code booknetic |
Wed, 26 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 26 Mar 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack | |
| Title | Booknetic < 4.1.5 - Staff Creation via CSRF | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-26T18:56:41.837Z
Reserved: 2025-01-05T23:26:04.781Z
Link: CVE-2024-13146
Updated: 2025-03-26T18:56:19.908Z
Status : Analyzed
Published: 2025-03-26T06:15:28.330
Modified: 2025-04-30T17:36:52.883
Link: CVE-2024-13146
No data.
OpenCVE Enrichment
No data.
EUVD