CVE-2024-6720

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Aug 6, 2024
Updated: Oct 28, 2024
CWE ID 352

Summary

CVE-2024-6720 is a vulnerability affecting the Light Poll WordPress plugin before version 1.0.0. This issue lacks Cross-Site Request Forgery (CSRF) protection in certain areas, allowing malicious actors to manipulate actions of logged-in users through specially crafted malicious requests. Successful exploitation could lead to unwanted changes or actions within the WordPress environment. It is essential to update the plugin to a secure version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share