CVE-2024-8200
Smashballoon
CVE-2024-8200: A Cross-Site Request Forgery (CSRF) vulnerability exists in the Reviews Feed WordPress plugin, potentially allowing unauthenticated attackers to modify the plugin's API key. This flaw affects versions up to and including 1.1.2 due to insufficient nonce validation in the 'update_api_key' function. An attacker could exploit this by tricking an administrator into clicking a malicious link, leading to the API key being updated with a value of their choosing. Despite a low SVRS score of 30, indicating a less critical immediate threat compared to others, the presence of CWE-352 highlights the fundamental security risk. Successful exploitation could compromise the integrity of the reviews displayed, potentially damaging the website's reputation or injecting malicious content. While the CVSS score is 0, security best practices suggest patching this vulnerability to prevent possible future exploits. Addressing this CSRF issue mitigates the risk of unauthorized API key changes and protects the site from potential manipulation via forged requests. Prompt updating of the plugin is recommended.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.