CVE-2024-6230

The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack
Configurations

Configuration 1 (hide)

cpe:2.3:a:wp-master:pardakht-delkhah:*:*:*:*:*:wordpress:*:*

History

02 Jan 2026, 20:19

Type Values Removed Values Added
First Time Wp-master pardakht-delkhah
Wp-master
CWE CWE-352
CPE cpe:2.3:a:wp-master:pardakht-delkhah:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/311e3c15-0f58-4f3b-91f8-0c62c0eea55e/ - () https://wpscan.com/vulnerability/311e3c15-0f58-4f3b-91f8-0c62c0eea55e/ - Exploit, Third Party Advisory

14 Mar 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

21 Nov 2024, 09:49

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/311e3c15-0f58-4f3b-91f8-0c62c0eea55e/ - () https://wpscan.com/vulnerability/311e3c15-0f58-4f3b-91f8-0c62c0eea55e/ -

01 Aug 2024, 22:15

Type Values Removed Values Added
Summary (en) The ?????? ?????? ?????? WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack (en) The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack

30 Jul 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) ?????? ?????? ?????? El complemento de WordPress hasta la versión 2.9.8 no tiene activada la verificación CSRF al restablecer sus campos de formulario, lo que podría permitir a los atacantes hacer que un administrador que haya iniciado sesión realice dicha acción a través de un ataque CSRF.
Summary (en) The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack (en) The ?????? ?????? ?????? WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack

30 Jul 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-30 06:15

Updated : 2026-01-02 20:19


NVD link : CVE-2024-6230

Mitre link : CVE-2024-6230

CVE.ORG link : CVE-2024-6230


JSON object : View

Products Affected

wp-master

  • pardakht-delkhah
CWE
CWE-352

Cross-Site Request Forgery (CSRF)