CVE-2024-5167

The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which could allow attackers to make a logged in admin add or delete settings from the blacklist or whitelist menu via a CSRF attack
Configurations

Configuration 1 (hide)

cpe:2.3:a:cminds:cm_e-mail_blacklist:*:*:*:*:*:wordpress:*:*

History

13 May 2025, 16:34

Type Values Removed Values Added
CWE CWE-352
References () https://wpscan.com/vulnerability/67bb5ab8-4493-4f5b-a989-41576675b61a/ - () https://wpscan.com/vulnerability/67bb5ab8-4493-4f5b-a989-41576675b61a/ - Exploit, Third Party Advisory
First Time Cminds
Cminds cm E-mail Blacklist
CPE cpe:2.3:a:cminds:cm_e-mail_blacklist:*:*:*:*:*:wordpress:*:*

21 Nov 2024, 09:47

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/67bb5ab8-4493-4f5b-a989-41576675b61a/ - () https://wpscan.com/vulnerability/67bb5ab8-4493-4f5b-a989-41576675b61a/ -

01 Aug 2024, 13:59

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

15 Jul 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) El complemento CM Email Registration Blacklist y Whitelist de WordPress anterior a 1.4.9 no tiene verificación CSRF al agregar o eliminar un elemento de la lista negra o blanca, lo que podría permitir a los atacantes hacer que un administrador que haya iniciado sesión agregue o elimine configuraciones de la lista negra o del menú de la lista blanca a través de un ataque CSRF

13 Jul 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-13 06:15

Updated : 2025-05-13 16:34


NVD link : CVE-2024-5167

Mitre link : CVE-2024-5167

CVE.ORG link : CVE-2024-5167


JSON object : View

Products Affected

cminds

  • cm_e-mail_blacklist
CWE
CWE-352

Cross-Site Request Forgery (CSRF)