CVE-2024-52446 HIGH

CVE-2024-52446: WordPress Buying Buddy IDX CRM plugin <= 1.2.8 - CSRF to PHP Object Injection vulnerability

Vendor Buying Buddy
Product Buying Buddy IDX CRM
Weakness CWE-352 · CSRF
Published November 20, 2024
Last update April 28, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in Buying Buddy Buying Buddy IDX CRM buying-buddy-idx-crm allows Object Injection.This issue affects Buying Buddy IDX CRM: from n/a through <= 1.2.8.

Explanation of Vulnerability in Simple Terms

02Summary

Buying Buddy IDX CRM versions up to 1.2.8 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in user, performs unauthorized actions on their behalf—such as modifying settings, creating records, or changing account details. The vulnerability requires user interaction (visiting a malicious link) but no special privileges.

What an attacker can do

03Attacker Capabilities

Perform unauthorized actions on a user's account without their knowledge, such as modifying settings or creating records.

Potential impact on your site

04Site Impact

Users' accounts and data can be modified or compromised through CSRF attacks if they visit untrusted websites while logged in.

Conditions required to exploit

05Prerequisites

Victim must be logged into Buying Buddy IDX CRM and visit an attacker-controlled webpage or click a malicious link.

Key dates

06Disclosure timeline

November 20, 2024 CVE published
April 28, 2026 Record updated