The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 14 May 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Stylemixthemes
Stylemixthemes cost Calculator Builder |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:stylemixthemes:cost_calculator_builder:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Stylemixthemes
Stylemixthemes cost Calculator Builder |
Wed, 18 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 18 Dec 2024 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. | |
| Title | Cost Calculator Builder < 3.2.43 - Settings update via CSRF | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2024-12-18T06:00:16.137Z
Updated: 2024-12-18T15:10:31.241Z
Reserved: 2024-11-05T18:26:45.843Z
Link: CVE-2024-10892
Updated: 2024-12-18T15:10:22.680Z
Status : Analyzed
Published: 2024-12-18T06:15:21.567
Modified: 2025-05-14T20:14:11.990
Link: CVE-2024-10892
No data.