Disable Auto Updates WordPress Plugin Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Disable Auto Updates plugin for WordPress, affecting all versions through 1.4. The issue arises from inadequate nonce validation on the 'disable-auto-updates' page, allowing unauthenticated attackers to disable auto updates by sending a forged request, provided they can persuade a site administrator to click a link.

Impact

Exploitation of this vulnerability allows for Cross-Site Request Forgery, where an attacker can trick a user into performing actions they did not intend to, potentially leading to the disabling of automatic updates on the WordPress site.

Remediation

No known patch is available. It is recommended to uninstall the affected plugin and find a replacement.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.