CVE-2024-13057 Details
Description
The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
A stored cross-site scripting vulnerability has been identified in the Dyn Business Panel WordPress plugin, affecting versions through 1.0.0. The issue arises because the plugin lacks proper cross-site request forgery (CSRF) checks in certain areas and fails to adequately sanitize and escape user input. This combination could enable attackers to exploit CSRF vulnerabilities, potentially leading to the injection of malicious scripts that are stored and executed later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/6f869a3d-1ac1-4d31-8fe5-9b9795b15b5b/ | CISA-ADP | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/6f869a3d-1ac1-4d31-8fe5-9b9795b15b5b/ | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| phycticio dyn business panel | 1.0.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 7, 2025 | Initial Analysis | [email protected] |
| Jan 27, 2025 | CVE Modified | CISA-ADP |
| Jan 27, 2025 | New CVE Received | [email protected] |