The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Metrics
Affected Vendors & Products
References
History
Tue, 22 Apr 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Felixker
Felixker wordpress\/plugin Upgrade Time Out Plugin |
|
Weaknesses | CWE-352 | |
CPEs | cpe:2.3:a:felixker:wordpress\/plugin_upgrade_time_out_plugin:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Felixker
Felixker wordpress\/plugin Upgrade Time Out Plugin |
Wed, 09 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 09 Apr 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
Title | Plugin Upgrade Time Out <= 1.0 - Stored XSS via CSRF | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-04-09T06:00:06.866Z
Updated: 2025-04-09T19:09:34.522Z
Reserved: 2024-08-27T19:29:41.723Z
Link: CVE-2024-8243

Updated: 2025-04-09T18:57:55.055Z

Status : Analyzed
Published: 2025-04-09T06:15:41.360
Modified: 2025-04-22T17:15:43.250
Link: CVE-2024-8243

No data.