The WP Finance WordPress plugin through 1.3.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Metrics
Affected Vendors & Products
References
History
Sat, 12 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Mon, 12 May 2025 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mch0lic
Mch0lic wp Finance |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:mch0lic:wp_finance:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Mch0lic
Mch0lic wp Finance |
Tue, 04 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Sat, 01 Feb 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WP Finance WordPress plugin through 1.3.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
Title | WP Finance <= 1.3.6 - Stored XSS via CSRF | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-02-01T06:00:11.746Z
Updated: 2025-02-04T20:48:51.013Z
Reserved: 2024-12-31T21:16:25.097Z
Link: CVE-2024-13096

Updated: 2025-02-04T20:48:44.512Z

Status : Analyzed
Published: 2025-02-01T06:15:30.837
Modified: 2025-05-12T01:01:02.617
Link: CVE-2024-13096

No data.