CVE-2024-2857

The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add button function, allowing unauthenticated users to call them either directly or via CSRF attacks. Furthermore, due to the lack of sanitisation and escaping, it could also allow them to perform Stored Cross-Site Scripting attacks against logged in admins.
Configurations

Configuration 1 (hide)

cpe:2.3:a:robbychen:simple_buttons_creator:*:*:*:*:*:wordpress:*:*

History

08 May 2025, 20:31

Type Values Removed Values Added
First Time Robbychen simple Buttons Creator
Robbychen
CPE cpe:2.3:a:robbychen:simple_buttons_creator:*:*:*:*:*:wordpress:*:*
CWE CWE-352
References () https://wpscan.com/vulnerability/b7a35c5b-474a-444a-85ee-c50782c7a6c2/ - () https://wpscan.com/vulnerability/b7a35c5b-474a-444a-85ee-c50782c7a6c2/ - Exploit, Third Party Advisory

21 Nov 2024, 09:10

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/b7a35c5b-474a-444a-85ee-c50782c7a6c2/ - () https://wpscan.com/vulnerability/b7a35c5b-474a-444a-85ee-c50782c7a6c2/ -

09 Aug 2024, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

15 Apr 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-15 05:15

Updated : 2025-05-08 20:31


NVD link : CVE-2024-2857

Mitre link : CVE-2024-2857

CVE.ORG link : CVE-2024-2857


JSON object : View

Products Affected

robbychen

  • simple_buttons_creator
CWE
CWE-352

Cross-Site Request Forgery (CSRF)