WP Customer Area, CVE-2024-12280
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jan 27, 2025
- Research Description
- The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which could allow attackers to make a logged in to delete them via a CSRF attack
- Affected versions
-
Min -, max 8.2.5.
- Status
-
vulnerable