4.3
CVSSv3

CVE-2024-13710

CVSSv4: NA | CVSSv3: 4.3 | CVSSv2: NA | VMScore: 530 | EPSS: 0.00012 | KEV: Not Included
Published: 25/03/2025 Updated: 25/03/2025

Vulnerability Summary

Cross-Site Request Forgery in Estatebud WordPress Plugin Before 5.5.0

The Estatebud – Properties & Listings WordPress plugin has a Cross-Site Request Forgery (CSRF) vulnerability in all versions up to and including 5.5.0. The issue stems from a lack of proper nonce validation on the 'estatebud_settings' page. This weakness allows unauthenticated attackers to modify plugin settings by tricking a site administrator into performing a specific action, such as clicking a malicious link.

Vulnerable Product Search on Vulmon Subscribe to Product

estatebud estatebud – properties & listings