A notable security vulnerability, identified as CVE-2024-6230, has been found in the Pardakht Delkhah WordPress plugin. This flaw, classified as a Cross-Site Request Forgery (CSRF) vulnerability, allows an attacker to trick a logged-in administrator into resetting the plugin’s form fields without their knowledge or consent. This could lead to unexpected changes in the plugin’s configuration, potentially disrupting its intended functionality on your WordPress site.
CVE Details
- Product Name: Pardakht Delkhah WordPress Plugin
- Published Date: July 30, 2024
- Severity: Medium (CVSS 6.5)
- Status: Analyzed
Affected Products
The vulnerability impacts the Pardakht Delkhah WordPress plugin across all versions up to and including 2.9.8. If you are running any version of this plugin prior to 2.9.9, your WordPress installation is at risk.
Current Status
This vulnerability has been officially analyzed and confirmed. Fortunately, a fix is available, making it crucial for users to take immediate action to secure their sites.
Severity Level
Rated with a CVSS score of 6.5, this CSRF vulnerability is considered of Medium severity. While it doesn’t directly allow an attacker to gain full control over your website or steal sensitive data, it can be exploited to perform unauthorized actions on behalf of a logged-in administrator. Specifically, an attacker could force the plugin’s settings to be reset, leading to data misconfiguration or disruption of services reliant on the plugin. This could impact the functionality of your payment forms or related features, requiring manual intervention to restore correct operation.
Possible Solutions
The most effective way to address this vulnerability is to update your Pardakht Delkhah WordPress plugin to the patched version. The developers have released a fix in version 2.9.9.
- Update Immediately: Ensure your Pardakht Delkhah plugin is updated to version 2.9.9 or later. Always back up your WordPress site before performing any plugin updates.
- Stay Vigilant: Regularly check for updates for all your WordPress plugins and themes. Keeping your software up-to-date is a fundamental cybersecurity practice.
- Implement Security Best Practices: Consider using a reputable WordPress security plugin that can help protect against CSRF and other common web vulnerabilities.
References
https://wpscan.com/vulnerability/311e3c15-0f58-4f3b-91f8-0c62c0eea55e/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6230


