CVE-2024-33681 HIGH

CVE-2024-33681: WordPress Regenerate post permalink plugin <= 1.0.3 - Cross Site Request Forgery (CSRF) leading to XSS vulnerability

Vendor Sandor Kovacs
Product Regenerate post permalink
Weakness CWE-352 · CSRF
Published April 29, 2024
Last update April 28, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in Sandor Kovacs Regenerate post permalink allows Cross-Site Scripting (XSS).This issue affects Regenerate post permalink: from n/a through 1.0.3.

Explanation of Vulnerability in Simple Terms

02Summary

The Regenerate post permalink plugin through version 1.0.3 is vulnerable to cross-site request forgery (CSRF). An attacker can trick a site administrator into visiting a malicious page that performs unauthorized actions on the site, such as regenerating post permalinks. The vulnerability requires user interaction and can affect the site's integrity and availability.

What an attacker can do

03Attacker Capabilities

Trick an admin into visiting a malicious page to perform unauthorized actions like regenerating post permalinks.

Potential impact on your site

04Site Impact

Attackers can manipulate post permalinks and other site settings if an admin visits a malicious link.

Conditions required to exploit

05Prerequisites

Admin must visit attacker-controlled page; no authentication bypass needed.

Key dates

06Disclosure timeline

April 29, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE