The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
History

Tue, 22 Apr 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Felixker
Felixker wordpress\/plugin Upgrade Time Out Plugin
Weaknesses CWE-352
CPEs cpe:2.3:a:felixker:wordpress\/plugin_upgrade_time_out_plugin:*:*:*:*:*:wordpress:*:*
Vendors & Products Felixker
Felixker wordpress\/plugin Upgrade Time Out Plugin

Wed, 09 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 06:15:00 +0000

Type Values Removed Values Added
Description The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Title Plugin Upgrade Time Out <= 1.0 - Stored XSS via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-04-09T06:00:06.866Z

Updated: 2025-04-09T19:09:34.522Z

Reserved: 2024-08-27T19:29:41.723Z

Link: CVE-2024-8243

cve-icon Vulnrichment

Updated: 2025-04-09T18:57:55.055Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-09T06:15:41.360

Modified: 2025-04-22T17:15:43.250

Link: CVE-2024-8243

cve-icon Redhat

No data.