CVE-2024-1230
CVE-2024-1230 affects the SimpleShop plugin for WordPress, exposing sites to Cross-Site Request Forgery (CSRF). Unauthenticated attackers can exploit this vulnerability to disconnect a site from SimpleShop by tricking an administrator into clicking a malicious link. The vulnerability exists in all versions up to 2.10.0 due to missing nonce validation in the 'maybe_disconnect_simpleshop' function. With an SVRS of 30, while not critical, this vulnerability should be addressed promptly to prevent unauthorized site modifications. Successful exploitation could disrupt e-commerce functionalities. Although the CVSS score is 0, indicating no direct impact, the CSRF risk should not be ignored for WordPress sites using the SimpleShop plugin. The 'In The Wild' tag suggests potential active exploitation, increasing the need for remediation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.