The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack
Metrics
Affected Vendors & Products
References
History
Tue, 20 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 15 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack | |
Title | Offload Videos – Bunny.net, AWS S3 <= 1.0.1 Subscriber+ CSRF | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-05-15T20:07:09.955Z
Updated: 2025-05-20T19:21:20.456Z
Reserved: 2024-07-12T19:51:37.943Z
Link: CVE-2024-6719

Updated: 2025-05-19T20:25:50.308Z

Status : Undergoing Analysis
Published: 2025-05-15T20:15:56.277
Modified: 2025-05-20T20:15:38.990
Link: CVE-2024-6719

No data.