CVE Database /
CVE-2024-33680
CVE · Medium
CVE-2024-33680 — MainWP Child Reports [mainwp-child-reports] < 2.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-33680
|
MainWP Child Reports [mainwp-child-reports] < 2.2 |
Cross-Site Request Forgery (CSRF) |
Medium
5.4
|
< 2.2
|
2.2 |
2024-04-26 |
—
|
CVE-2024-33680
The MainWP Child Reports plugin for WordPress contains a cross-site request forgery vulnerability affecting versions 2.1.1 and earlier, stemming from inadequate nonce verification in the uninstall() function. An unauthenticated attacker could exploit this flaw to deactivate the plugin by crafting a malicious request and deceiving a site administrator into clicking a link or performing a similar action. The vulnerability was remedied in version 2.2.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings