The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.
History

Mon, 12 May 2025 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Ombu
Ombu bulk Me Now\!
Weaknesses CWE-352
CPEs cpe:2.3:a:ombu:bulk_me_now\!:*:*:*:*:*:wordpress:*:*
Vendors & Products Ombu
Ombu bulk Me Now\!

Thu, 30 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jan 2025 06:15:00 +0000

Type Values Removed Values Added
Description The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.
Title Bulk Me Now <= 2.0 - Message Deletion via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-01-30T06:00:11.424Z

Updated: 2025-01-30T15:26:36.949Z

Reserved: 2024-12-17T16:01:52.002Z

Link: CVE-2024-12709

cve-icon Vulnrichment

Updated: 2025-01-30T15:26:23.661Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-30T06:15:29.557

Modified: 2025-05-11T23:49:34.387

Link: CVE-2024-12709

cve-icon Redhat

No data.