Description
WordPress Plugin Dean's Permalinks Migration is prone to a vulnerability which can be exploited by malicious people to conduct cross-site request forgery attacks. The vulnerability is caused due to the application allowing users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited to e.g. conduct script insertion attacks against the PermalinksMigration page. WordPress Plugin Dean's Permalinks Migration version 1.0 is vulnerable; other versions may also be affected.
Remediation
Do not browse untrusted websites while logged on to WordPress
References
Related Vulnerabilities
Plone CMS Weak Password Requirements Vulnerability (CVE-2020-7940)
AbanteCart Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-26521)
Multiple SugarCRM Products Remote Code Execution Vulnerability (CVE-2023-22952)
Envoy Proxy Improper Encoding or Escaping of Output Vulnerability (CVE-2024-45808)