The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Metrics
Affected Vendors & Products
References
History
Thu, 15 May 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mranderson
Mranderson base64 Encoderdecoder |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:mranderson:base64_encoderdecoder:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Mranderson
Mranderson base64 Encoderdecoder |
Thu, 27 Mar 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 20 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-05-15T06:00:05.094Z
Updated: 2025-03-27T21:05:29.653Z
Reserved: 2024-04-15T14:54:51.741Z
Link: CVE-2024-3823

Updated: 2024-08-01T20:20:02.164Z

Status : Analyzed
Published: 2024-05-15T06:15:14.650
Modified: 2025-05-15T13:28:00.860
Link: CVE-2024-3823

No data.