CVE-2024-4541 is a Cross-Site Request Forgery (CSRF) vulnerability affecting all versions up to 3.0.0 of the Custom Product List Table plugin for WordPress. This flaw stems from inadequate nonce validation, allowing unauthenticated attackers to manipulate products (add, delete, bulk edit, approve, or cancel) if they can trick an administrator into clicking a malicious link. The vulnerability carries a CVSS score of 4.3 (MEDIUM), indicating a network-based attack with low complexity, requiring user interaction, and resulting in low integrity impact (data modification) without affecting confidentiality or availability. Its EPSS and FAUCET Risk Scores are very low, suggesting a minimal likelihood of exploitation in the wild. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are also absent, indicating a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Viitorcloudvc | Custom Product List Table | >= 0, <= 3.0.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.