← WordPress Vulnerabilities
WordPress security by component

Auto Refresh Single Page

Auto Refresh Single Page is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Mar 05, 2024; the highest published CVSS base score is 8.8.

Plugin slug: auto-refresh-single-page

CVE-2024-1731: Auto Refresh Single Page: Code execution

Auto Refresh Single Page is affected by code execution. Exploitation requires an authenticated contributor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedMar 05, 2024
Safe version guidanceSee mitigation notes
Published vulnerabilities for auto-refresh-single-page
Safe version
Mar 05, 2024 CVE-2024-1731
Auto Refresh Single Page: Code execution
Auto Refresh Single Page is affected by code execution. Exploitation requires an authenticated contributor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVDPending