The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
Metrics
Affected Vendors & Products
References
History
Tue, 13 May 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cminds
Cminds cm Search And Replace |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:cminds:cm_search_and_replace:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Cminds
Cminds cm Search And Replace |

Status: PUBLISHED
Assigner: WPScan
Published: 2024-07-13T06:00:07.447Z
Updated: 2024-08-01T21:03:09.657Z
Reserved: 2024-05-16T18:56:23.800Z
Link: CVE-2024-5028

Updated: 2024-08-01T21:03:09.657Z

Status : Analyzed
Published: 2024-07-13T06:15:03.563
Modified: 2025-05-13T16:39:26.863
Link: CVE-2024-5028

No data.