Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54166 | The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack |
Fri, 29 Aug 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xavivars
Xavivars xv Random Quotes |
|
| CPEs | cpe:2.3:a:xavivars:xv_random_quotes:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Xavi.ivars
Xavi.ivars xv Random Quotes |
Xavivars
Xavivars xv Random Quotes |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 06 May 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xavi.ivars
Xavi.ivars xv Random Quotes |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:xavi.ivars:xv_random_quotes:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Xavi.ivars
Xavi.ivars xv Random Quotes |
Tue, 11 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 11 Mar 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack | |
| Title | XV Random Quotes <= 1.40 - Settings Reset via CSRF | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-11T14:43:42.684Z
Reserved: 2025-01-21T14:25:41.141Z
Link: CVE-2024-13580
Updated: 2025-03-11T14:43:04.211Z
Status : Analyzed
Published: 2025-03-11T06:15:25.813
Modified: 2025-08-29T16:39:17.303
Link: CVE-2024-13580
No data.
OpenCVE Enrichment
No data.
EUVD