CVE-2024-6719

The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack
Configurations

Configuration 1 (hide)

cpe:2.3:a:webgarh:offload_videos:*:*:*:*:*:wordpress:*:*

History

05 Jan 2026, 18:11

Type Values Removed Values Added
First Time Webgarh offload Videos
Webgarh
References () https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/ - () https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/ - Third Party Advisory, Exploit
CPE cpe:2.3:a:webgarh:offload_videos:*:*:*:*:*:wordpress:*:*
CWE CWE-352

20 May 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
References () https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/ - () https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/ -

16 May 2025, 14:42

Type Values Removed Values Added
Summary
  • (es) El complemento Offload Videos de WordPress anterior a la versión 1.0.1 no tiene la comprobación CSRF activada al actualizar su configuración, lo que podría permitir que usuarios con bajos privilegios la actualicen mediante un ataque CSRF.

15 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2026-01-05 18:11


NVD link : CVE-2024-6719

Mitre link : CVE-2024-6719

CVE.ORG link : CVE-2024-6719


JSON object : View

Products Affected

webgarh

  • offload_videos
CWE
CWE-352

Cross-Site Request Forgery (CSRF)