CVE-2024-0374

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 5, 2024
Updated: Feb 10, 2024
CWE ID 352

Summary

CVE-2024-0374 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Views for WPForms plugin for WordPress. Versions up to and including 3.2.2 are impacted by this issue. The 'create_view' function, which allows users to create views for WPForms entries on a site's frontend, lacks proper nonce validation. This security weakness enables unauthenticated attackers to create views through malicious requests, provided they can induce a site administrator to perform an action like clicking on a malicious link.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share