CVE · High

CVE-2024-5551 — WP Staging Pro [wp-staging-pro] < 5.6.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5551 WP Staging Pro [wp-staging-pro] < 5.6.1 Cross-Site Request Forgery (CSRF) High 8.8 < 5.6.1 5.6.1 2024-06-13

CVE-2024-5551

WP Staging Pro plugin versions up to 5.6.0 are susceptible to cross-site request forgery attacks because the plugin fails to properly validate nonce tokens on the 'sub' parameter. An unauthenticated attacker could exploit this vulnerability by crafting a malicious request that, if clicked by a site administrator, allows the inclusion of arbitrary local files ending in '-settings.php'. The vulnerability is resolved in version 5.6.1 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.