CVE-2024-6023: Adamsolymosi Contentlock
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in admin perform such action via a CSRF attack
Affected products
- Adamsolymosi Contentlock: before 1.0.4 (fixed in 1.0.4)
Published 2024-07-12. Last modified 2026-06-17.