CVE-2024-3472: Modal Window < 5.3.10 - Modal Deletion via CSRF
Published May 2, 2024
·Updated
The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack
Affected Software
2 affected components
WordPress Modal Window<5.3.10
Wow-Company Modal Window WordPress<5.3.10
Event History
May 2, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3472?
CVE-2024-3472 is considered a high severity vulnerability due to the potential for CSRF attacks against admin users.
2
How do I fix CVE-2024-3472?
To mitigate CVE-2024-3472, you should update the Modal Window WordPress plugin to version 5.3.10 or later.
3
Who is affected by CVE-2024-3472?
CVE-2024-3472 affects installations of the Modal Window WordPress plugin prior to version 5.3.10.
4
What type of vulnerability is CVE-2024-3472?
CVE-2024-3472 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
What can attackers achieve with CVE-2024-3472?
Attackers can exploit CVE-2024-3472 to force a logged-in admin to delete modals without their consent.