WordPress Challan Plugin Cross-Site Request Forgery Vulnerability Allowing Privilege Escalation

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WordPress Challan plugin, specifically in versions through 3.7.58. This vulnerability allows for privilege escalation by forcing higher-privileged users to perform unintended actions under their current authentication.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed by users with higher privileges, potentially allowing for further escalation or abuse of those privileges.

Remediation

Users of the WordPress Challan plugin should update to version 3.7.59 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.