CVE-2024-31936
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Apr 11, 2024
CWE ID 352
Summary
CVE-2024-31936 is a Cross-Site Request Forgery (CSRF) vulnerability affecting UsersWP, a plugin developed by AyeCode Ltd. This issue allows an attacker to trick a user into performing unwanted actions on a web application, potentially leading to unauthorized changes or data access. The vulnerability is found in versions of UsersWP before 1.2.6, and users are advised to update to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share