CVE · Medium

CVE-2024-0592 — Related Posts for WordPress [related-posts-for-wp] < 2.2.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-0592 Related Posts for WordPress [related-posts-for-wp] < 2.2.2 Cross-Site Request Forgery (CSRF) Medium 5.4 < 2.2.2 2.2.2 2024-03-13

CVE-2024-0592

The Related Posts for WordPress plugin through version 2.2.1 contains a cross-site request forgery vulnerability in the handle_create_link() function due to insufficient nonce verification. An unauthenticated attacker could exploit this flaw by tricking a site administrator into clicking a malicious link, allowing the attacker to create related post associations on arbitrary posts. This vulnerability could enable attackers to gain unauthorized access to draft and password-protected content.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.