CVE-2024-2405 Vulnerability Details

  /     /     /  

CVE-2024-2405 Metadata Quick Info

CVE Published: 02/05/2024 | CVE Updated: 01/08/2024 | CVE Year: 2024
Source: WPScan | Vendor: Unknown | Product: Float menu
Status : PUBLISHED

CVE-2024-2405 Description

The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: CWE-352 Cross-Site Request Forgery (CSRF)
Source: Unknown

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).