CVE-2024-0374
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 5, 2024
Updated: Feb 10, 2024
CWE ID 352
Summary
CVE-2024-0374 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Views for WPForms plugin for WordPress. Versions up to and including 3.2.2 are impacted by this issue. The 'create_view' function, which allows users to create views for WPForms entries on a site's frontend, lacks proper nonce validation. This security weakness enables unauthenticated attackers to create views through malicious requests, provided they can induce a site administrator to perform an action like clicking on a malicious link.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share