CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-56236: WordPress Hestia Nginx Cache plugin <= 2.4.0 - Cross Site Request Forgery (CSRF) vulnerability

4.3 CVSS

Description

Missing Authorization vulnerability in Jakob Bouchard Hestia Nginx Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hestia Nginx Cache: from n/a through 2.4.0.

Classification

CVE ID: CVE-2024-56236

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.3

Affected Products

Vendor: Jakob Bouchard

Product: Hestia Nginx Cache

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.48% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://patchstack.com/database/wordpress/plugin/hestia-nginx-cache/vulnerability/wordpress-hestia-nginx-cache-plugin-2-4-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve

Timeline