CVE-2024-31371
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-31371 denotes a Cross-Site Request Forgery (CSRF) vulnerability identified in Xylus Themes' WP Event Aggregator plugin. Affecting versions from n/a to 1.7.6, this issue allows attackers to manipulate users, potentially forcing them to perform unintended actions or access sensitive data. By deceiving users into clicking a malicious link, attackers can submit unauthorized requests on behalf of the user, posing a significant security risk. It is essential for users to update the WP Event Aggregator plugin to a patched version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.