Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4726 | The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'disable-auto-updates' page. This makes it possible for unauthenticated attackers to disable all auto updates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. |
Wed, 19 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Feb 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the 'disable-auto-updates' page. This makes it possible for unauthenticated attackers to disable all auto updates via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
| Title | Disable Auto Updates <= 1.4 - Cross-Site Request Forgery to Auto-update Disable | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:56:34.874Z
Reserved: 2025-01-10T18:18:35.398Z
Link: CVE-2024-13336
Updated: 2025-02-19T19:47:59.431Z
Status : Received
Published: 2025-02-19T09:15:09.083
Modified: 2025-02-19T09:15:09.083
Link: CVE-2024-13336
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:42:24Z
EUVD