CVE Feed

    Dashboard / CVE / CVE-2024-39680

    CVE-2024-39680

    Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they didn't intend to perform under their current authentication. This issue has been addressed in release version 1.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:Jul 17, 2024
    Last Modified:Feb 10, 2025
    EPS:Jul 17, 2024
    EPSS Score:0.00324
    CVSS Score:5.4

    Affected Products

    Vendor
    Boxystudio
    Product
    Cooked

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High