CVE-2024-32537

7.1

joshuae1974 · Flash Video Player

A Cross-Site Request Forgery (CSRF) vulnerability in the joshuae1974 Flash Video Player plugin for WordPress allows remote attackers to perform unauthorized actions on behalf of authenticated users.

Executive summary

The joshuae1974 Flash Video Player plugin is vulnerable to Cross-Site Request Forgery, potentially allowing unauthenticated attackers to perform unauthorized actions within the WordPress environment.

Vulnerability

The plugin suffers from a CSRF vulnerability, categorized as CWE-352, which can be triggered by an unauthenticated attacker to induce a victim to execute unintended actions without their consent.

Business impact

The vulnerability carries a CVSS score of 7.1, indicating a high severity risk that could lead to unauthorized administrative changes or data manipulation within the WordPress installation. Successful exploitation may result in the compromise of site integrity, potential unauthorized access to sensitive plugin settings, and broader reputational damage if the plugin is used to facilitate malicious redirects or site defacement.

Remediation

Immediate Action: Users should immediately disable or remove the Flash Video Player plugin until a security patch is provided by the developer, as no official fix is currently confirmed.

Proactive Monitoring: Review web server and WordPress access logs for suspicious requests originating from unexpected sources or unusual HTTP referrers that may indicate CSRF attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with robust CSRF protection enabled to inspect incoming requests and block suspicious patterns targeting the plugin.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the absence of a confirmed vendor patch, the risk to the environment is significant. Administrators must prioritize the deactivation of the Flash Video Player plugin to prevent potential exploitation and should monitor the vendor's repository for future updates that address this security flaw.

Sources

Originally found and disclosed by Dimas Maulana | Patchstack Bug Bounty Program, per the CVE Program record.