The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding them as employees.
Metrics
Affected Vendors & Products
References
History
Mon, 05 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Theinnovs
Theinnovs innovs Hr |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:theinnovs:innovs_hr:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Theinnovs
Theinnovs innovs Hr |
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T15:24:33.234Z
Reserved: 2024-01-24T11:59:39.530Z
Link: CVE-2024-0858
No data.
Status : Analyzed
Published: 2024-03-18T19:15:06.530
Modified: 2025-05-05T18:55:59.967
Link: CVE-2024-0858
No data.