{"id":"CVE-2024-3824","title":"The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack","summary":"The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","cwe":["CWE-352"],"vendor":"mranderson","product":"base64_encoder/decoder","affected":["base64_encoder/decoder <= 0.9.2"],"published":"2024-05-15","updated":"2026-07-29","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-3824","references":[{"url":"https://wpscan.com/vulnerability/749ae334-b1d1-421e-a04c-35464c961a4a/","label":"contact@wpscan.com"},{"url":"https://wpscan.com/vulnerability/749ae334-b1d1-421e-a04c-35464c961a4a/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00204,"epssPercentile":0.10692,"ingestedAt":"2026-07-29T14:48:16.286Z","slug":"CVE-2024-3824","body":"## Overview\n\nThe Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack\n\n## Affected\n\n- `base64_encoder/decoder <= 0.9.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}