CVE-2024-5551
WP Staging Pro plugin versions up to 5.6.0 are susceptible to cross-site request forgery attacks because the plugin fails to properly validate nonce tokens on the 'sub' parameter. An unauthenticated attacker could exploit this vulnerability by crafting a malicious request that, if clicked by a site administrator, allows the inclusion of arbitrary local files ending in '-settings.php'. The vulnerability is resolved in version 5.6.1 and later.
Based on public CVE data (MITRE/NVD).