CVE-2024-7386

CVSS V2 None CVSS V3 None
Description
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to missing nonce validation on the wpdmpp_async_request() function. This makes it possible for unauthenticated attackers to perform actions such as initiating refunds via a forged request granted they can trick a site administrator or shop manager into performing an action such as clicking on a link.
Overview
  • CVE ID
  • CVE-2024-7386
  • Assigner
  • Wordfence
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-09-25T02:04:58.768Z
  • Last Modified Date
  • 2024-09-25T02:04:58.768Z
History
Created Old Value New Value Data Type Notes
2024-10-06 10:56:10 Added to TrackCVE