CVE-2024-38754 Overview
CVE-2024-38754 is a Cross-Site Request Forgery (CSRF) vulnerability in the Taggbox taggbox-widget plugin for WordPress. The flaw affects all versions up to and including 3.3. An attacker can trick an authenticated user into submitting a forged request that performs unintended actions within the plugin. Exploitation requires user interaction, typically by luring a logged-in victim to visit an attacker-controlled page. The vulnerability is tracked under CWE-352: Cross-Site Request Forgery.
Critical Impact
Successful exploitation allows an attacker to perform state-changing actions on the WordPress site under the context of an authenticated user, potentially altering plugin configuration or widget content.
Affected Products
- Taggbox taggbox-widget WordPress plugin versions up to and including 3.3
- WordPress installations with the Taggbox widget enabled
- Sites where administrators or privileged users interact with untrusted content while authenticated
Discovery Timeline
- 2025-01-02 - CVE-2024-38754 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-38754
Vulnerability Analysis
The Taggbox taggbox-widget plugin fails to validate the origin and intent of state-changing HTTP requests. WordPress provides a nonce mechanism through wp_nonce_field() and check_admin_referer() to prevent CSRF, but the vulnerable plugin endpoints do not enforce these checks properly. An attacker crafts a malicious page containing an auto-submitting form or image tag targeting a plugin endpoint. When a logged-in WordPress user visits the page, the browser submits the request with the user's active session cookies. The plugin processes the action as if it originated from the legitimate user. According to the Patchstack WordPress Vulnerability Report, all versions through 3.3 are affected. The EPSS probability is approximately 0.19%, indicating low observed exploitation activity.
Root Cause
The root cause is missing or improperly validated anti-CSRF tokens on plugin request handlers. Without a verified nonce, the plugin cannot distinguish between a user-initiated action and a forged cross-origin request. This maps directly to CWE-352.
Attack Vector
Exploitation occurs over the network and requires user interaction. An attacker hosts a page that issues a background request to the target WordPress site. If a plugin administrator visits the page while authenticated, the browser attaches session cookies and the plugin executes the attacker-supplied action. No credentials are required from the attacker directly. The impact is limited to integrity of plugin-managed data; confidentiality and availability are not affected per the CVSS vector.
No public proof-of-concept code is available. Refer to the Patchstack advisory for additional technical detail.
Detection Methods for CVE-2024-38754
Indicators of Compromise
- Unexpected changes to Taggbox widget settings or embedded feeds that do not correspond to administrator activity
- HTTP POST requests to Taggbox plugin endpoints with Referer headers pointing to external, untrusted domains
- Administrator sessions submitting plugin actions immediately after visiting third-party links
Detection Strategies
- Review web server access logs for state-changing requests to /wp-admin/admin-post.php or /wp-admin/admin-ajax.php referencing Taggbox actions with off-site referrers
- Inspect WordPress audit logs for plugin configuration changes not correlated with authenticated administrator UI activity
- Correlate browser proxy or endpoint telemetry with WordPress admin actions to identify cross-origin submissions
Monitoring Recommendations
- Deploy a Web Application Firewall (WAF) rule that inspects requests to Taggbox plugin endpoints for missing or invalid _wpnonce parameters
- Alert on administrator sessions initiating plugin actions with a Referer header outside the site's own origin
- Retain WordPress admin activity logs for a minimum of 90 days to support incident review
How to Mitigate CVE-2024-38754
Immediate Actions Required
- Update the Taggbox taggbox-widget plugin to a version later than 3.3 as soon as a fix is published by the vendor
- Restrict administrator accounts from browsing untrusted sites while authenticated to WordPress
- Enforce short session lifetimes and require re-authentication for sensitive plugin actions
Patch Information
Consult the Patchstack advisory for the latest patch status. All versions from initial release through 3.3 are affected. If no patched version is available, apply the workarounds below.
Workarounds
- Disable and remove the Taggbox taggbox-widget plugin until a patched release is available
- Deploy a WAF policy that requires a valid _wpnonce parameter and same-origin Referer header for Taggbox plugin endpoints
- Use browser isolation or a dedicated administration browser profile for WordPress administrative work
# Example WAF rule concept: block cross-origin POSTs to Taggbox endpoints
# ModSecurity-style pseudo-rule
SecRule REQUEST_URI "@contains taggbox" \
"chain,deny,status:403,id:1002024387540,msg:'CVE-2024-38754 CSRF block'"
SecRule REQUEST_METHOD "@streq POST" \
"chain"
SecRule &ARGS:_wpnonce "@eq 0"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
