CVE-2024-0592
The Related Posts for WordPress plugin through version 2.2.1 contains a cross-site request forgery vulnerability in the handle_create_link() function due to insufficient nonce verification. An unauthenticated attacker could exploit this flaw by tricking a site administrator into clicking a malicious link, allowing the attacker to create related post associations on arbitrary posts. This vulnerability could enable attackers to gain unauthorized access to draft and password-protected content.
Based on public CVE data (MITRE/NVD).