CVE-2024-52421
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2024-52421 is a newly disclosed vulnerability that impacts the WP Popup Window Maker plugin for WordPress. This issue combines a Cross-Site Request Forgery (CSRF) weakness with the potential for Stored Cross-Site Scripting (XSS) attacks. Malicious actors can exploit this vulnerability, which affects versions of WP Popup Window Maker ranging from undisclosed to 2.0, to inject malicious scripts into unsuspecting users' browsers. As a result, attackers may execute unauthorized actions and steal sensitive data. Users are strongly advised to update to the latest version of the plugin or consider disabling it until a patch is released.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.