CVE-2024-6719

T

he Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack

Configurations

Configuration 1 (hide)

cpe:2.3:a:webgarh:offload_videos:*:*:*:*:*:wordpress:*:*

History

05 Jan 2026, 18:11

Type Values Removed Values Added
First Time Webgarh
Webgarh offload Videos
CPE cpe:2.3:a:webgarh:offload_videos:*:*:*:*:*:wordpress:*:*
CWE CWE-352
References () https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/ - () https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/ - Third Party Advisory, Exploit

20 May 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
References () https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/ - () https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/ -

16 May 2025, 14:42

Type Values Removed Values Added
Summary
  • (es) El complemento Offload Videos de WordPress anterior a la versión 1.0.1 no tiene la comprobación CSRF activada al actualizar su configuración, lo que podría permitir que usuarios con bajos privilegios la actualicen mediante un ataque CSRF.

15 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2026-01-05 18:11


NVD link : CVE-2024-6719

Mitre link : CVE-2024-6719

CVE.ORG link : CVE-2024-6719


JSON object : View

Products Affected
CWE
CWE-352

Cross-Site Request Forgery (CSRF)