Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-8243


The WordPress/Plugin Upgrade Time Out Plugin WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.


Published

2025-04-09T06:15:41.360

Last Modified

2025-04-22T17:15:43.250

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application felixker wordpress\/plugin_upgrade_time_out_plugin ≤ 1.0 Yes

References