Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • The top inclusive marketing trends of 2025, according to Sonia Thompson
    • Top social media tools to boost your social strategy
    • B2B marketing team structures every company should consider
    • Instagram Reels Trends to Use in 2025 (Updated Weekly)
    • What Is an Email Blast? Your Guide to Modern Blast Email Marketing
    • What Is CTOR? Everything You Need to Know About Click to Open Rate in Email Marketing
    • 7 Huge Content Marketing Challenges in 2025 (+How to Overcome Them)
    • What Does a Full Funnel Strategy for Meta Ads Look Like in 2025?
    YGLuk
    • Home
    • MsLi
      • MsLi’s Digital Products
      • MsLi’s Social Connections
    • Tiktok Specialist
    • TikTok Academy
    • Digital Marketing
    • Influencer Marketing
    • More
      • SEO
      • Digital Marketing Tips
      • Email Marketing
      • Content Marketing
      • SEM
      • Website Traffic
      • Marketing Trends
    YGLuk
    Home » SEO
    SEO

    WordPress Nested Pages Plugin High Severity Vulnerability

    YGLukBy YGLukJuly 8, 2024No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    The U.S. Nationwide Vulnerability Database (NVD) and Wordfence printed a safety advisory of a excessive severity Cross Web site Request Forgery (CSRF) vulnerability affecting the Nested Pages WordPress plugin affecting as much as +100,000 installations. The vulnerability obtained a Widespread Vulnerability Scoring System (CVSS) ranking of 8.8 on a scale of 1 – 10, with ten representing the very best degree severity.

    Cross Web site Request Forgery (CSRF)

    The Cross Web site Request Forgery (CSRF) is a kind of assault that takes benefit of a safety flaw within the Nested Pages plugin that enables unauthenticated attackers to name (execute) PHP recordsdata, that are the code degree recordsdata of WordPress.

    There’s a lacking or incorrect nonce validation, which is a standard safety function utilized in WordPress plugins to safe types and URLs. A second flaw within the plugin is a lacking safety function referred to as sanitization. Sanitization is a technique of securing knowledge that’s enter or output which can be frequent to WordPress plugins however on this case is lacking.

    Based on Wordfence:

    “This is because of lacking or incorrect nonce validation on the ‘settingsPage’ perform and lacking santization of the ‘tab’ parameter.”

    The CSRF assault depends on getting a signed in WordPress person (like an Administrator) to click on a hyperlink which in flip permits the attacker to finish the assault. This vulnerability is rated 8.8 which makes it a excessive severity menace. To place that into perspective, a rating of 8.9 is a vital degree menace which is a good larger degree. So at 8.8 it’s simply wanting a vital degree menace.

    This vulnerability impacts all variations of the Nested Pages plugin as much as and together with model 3.2.7. The builders of the plugin launched a safety repair in model 3.2.8 and responsibly printed the small print of the safety replace of their changelog.

    The official changelog paperwork the safety repair:

    “Safety replace addressing CSRF difficulty in plugin settings”

    Learn the advisory at Wordfence:

    Nested Pages <= 3.2.7 – Cross-Site Request Forgery to Local File Inclusion

    Learn the advisory on the NVD:

    CVE-2024-5943 Detail

    Featured Picture by Shutterstock/Dean Drobot



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    YGLuk
    • Website

    Related Posts

    Using Google Merchant Center Next For Competitive Analysis

    December 2, 2024

    The Definitive Guide For Your Online Store

    December 2, 2024

    Bluesky Emerges As Traffic Source: Publishers Report 3x Engagement

    December 2, 2024

    Google Chrome site engagement service metrics

    December 2, 2024
    Add A Comment
    Leave A Reply Cancel Reply

    6 + 9 =

    Top Posts

    The top inclusive marketing trends of 2025, according to Sonia Thompson

    May 9, 2025

    Top social media tools to boost your social strategy

    May 9, 2025

    B2B marketing team structures every company should consider

    May 9, 2025

    Instagram Reels Trends to Use in 2025 (Updated Weekly)

    May 9, 2025

    What Is an Email Blast? Your Guide to Modern Blast Email Marketing

    May 8, 2025
    Categories
    • Content Marketing
    • Digital Marketing
    • Digital Marketing Tips
    • Email Marketing
    • Influencer Marketing
    • Marketing Trends
    • SEM
    • SEO
    • TikTok Academy
    • Tiktok Specialist
    • Website Traffic
    About us

    Welcome to YGLuk.com – Your Gateway to Digital Success!

    At YGLuk, we are passionate about the ever-evolving world of Digital Marketing and Influencer Marketing. Our mission is to empower businesses and individuals to thrive in the digital landscape by providing valuable insights, expert advice, and the latest trends in the dynamic realm of online marketing.

    We are committed to providing valuable, reliable, and up-to-date information to help you navigate the digital landscape successfully. Whether you are a seasoned professional or just starting, YGLuk is your one-stop destination for all things digital marketing and influencer marketing.

    Top Insights

    The top inclusive marketing trends of 2025, according to Sonia Thompson

    May 9, 2025

    Top social media tools to boost your social strategy

    May 9, 2025

    B2B marketing team structures every company should consider

    May 9, 2025
    Categories
    • Content Marketing
    • Digital Marketing
    • Digital Marketing Tips
    • Email Marketing
    • Influencer Marketing
    • Marketing Trends
    • SEM
    • SEO
    • TikTok Academy
    • Tiktok Specialist
    • Website Traffic
    Copyright © 2024 Ygluk.com All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.