---
id: CVE-2024-3823
title: >-
  The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF
  check when updating its settings, and is missing sanitisation as well as
  escaping, which could allow attackers to make logged in admin add Stored XSS
  payloads v…
summary: >-
  The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF
  check when updating its settings, and is missing sanitisation as well as
  escaping, which could allow attackers to make logged in admin add Stored XSS
  payloads v…
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-352
vendor: mranderson
product: base64_encoder/decoder
affected:
  - base64_encoder/decoder <= 0.9.2
published: '2024-05-15'
updated: '2026-07-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-3823'
references:
  - url: 'https://wpscan.com/vulnerability/a138215c-4b8c-4182-978f-d21ce25070d3/'
    label: contact@wpscan.com
  - url: 'https://wpscan.com/vulnerability/a138215c-4b8c-4182-978f-d21ce25070d3/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00219
epssPercentile: 0.10946
ingestedAt: '2026-07-29T14:48:16.238Z'
---

## Overview

The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

## Affected

- `base64_encoder/decoder <= 0.9.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
