CVE-2024-6720
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Aug 6, 2024
Updated: Oct 28, 2024
CWE ID 352
Summary
CVE-2024-6720 is a vulnerability affecting the Light Poll WordPress plugin before version 1.0.0. This issue lacks Cross-Site Request Forgery (CSRF) protection in certain areas, allowing malicious actors to manipulate actions of logged-in users through specially crafted malicious requests. Successful exploitation could lead to unwanted changes or actions within the WordPress environment. It is essential to update the plugin to a secure version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share