The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
Metrics
Affected Vendors & Products
References
History
Thu, 15 May 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mranderson
Mranderson base64 Encoderdecoder |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:mranderson:base64_encoderdecoder:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Mranderson
Mranderson base64 Encoderdecoder |
Thu, 27 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 20 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published: 2024-05-15T06:00:05.094Z
Updated: 2025-03-27T21:05:29.653Z
Reserved: 2024-04-15T14:54:51.741Z
Link: CVE-2024-3823
Updated: 2024-08-01T20:20:02.164Z
Status : Analyzed
Published: 2024-05-15T06:15:14.650
Modified: 2025-05-15T13:28:00.860
Link: CVE-2024-3823
No data.
ReportizFlow