Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-5284


The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack


Published

2024-07-13T06:15:04.617

Last Modified

2025-05-19T14:59:16.240

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tipsandtricks-hq wp_affiliate_platform < 6.5.1 Yes

References