CVE-2024-4218

The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to plugin improperly releasing the tagged and patched version of the plugin - the vulnerable version is used as the core files, while the patched version was included in a 'trunk' folder. This makes it possible for unauthenticated attackers to perform a variety of actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Configurations

No configuration.

History

08 Apr 2026, 17:18

Type Values Removed Values Added
References
  • () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3094146%40affieasy&new=3094146%40affieasy&sfp_email=&sfph_mail= -
CWE CWE-352
Summary (en) The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.7. This is due to plugin improperly releasing the tagged and patched version of the plugin - the vulnerable version is used as the core files, while the patched version was included in a 'trunk' folder. This makes it possible for unauthenticated attackers to perform a variety of actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. (en) The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to plugin improperly releasing the tagged and patched version of the plugin - the vulnerable version is used as the core files, while the patched version was included in a 'trunk' folder. This makes it possible for unauthenticated attackers to perform a variety of actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

21 Nov 2024, 09:42

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/browser/affieasy/tags/1.1.6 - () https://plugins.trac.wordpress.org/browser/affieasy/tags/1.1.6 -
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/095a2262-1da2-4f79-896c-6d48eb079a7b?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/095a2262-1da2-4f79-896c-6d48eb079a7b?source=cve -

30 May 2024, 13:15

Type Values Removed Values Added
Summary
  • (es) El complemento AffiEasy para WordPress es vulnerable a Cross-Site Request Forgery en todas las versiones hasta la 1.1.7 incluida. Esto se debe a que el complemento publicó incorrectamente la versión etiquetada y parcheada del complemento: la versión vulnerable se usa como archivos principales, mientras que la versión parcheada se incluyó en una carpeta "troncal". Esto hace posible que atacantes no autenticados realicen una variedad de acciones a través de una solicitud falsificada, siempre que puedan engañar al administrador del sitio para que realice una acción como hacer clic en un enlace.

30 May 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-30 05:15

Updated : 2026-06-17 08:01


NVD link : CVE-2024-4218

Mitre link : CVE-2024-4218

CVE.ORG link : CVE-2024-4218


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)