First published: Thu May 02 2024(Updated: )
The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Modal Window | <5.3.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3472 is considered a high severity vulnerability due to the potential for CSRF attacks against admin users.
To mitigate CVE-2024-3472, you should update the Modal Window WordPress plugin to version 5.3.10 or later.
CVE-2024-3472 affects installations of the Modal Window WordPress plugin prior to version 5.3.10.
CVE-2024-3472 is a Cross-Site Request Forgery (CSRF) vulnerability.
Attackers can exploit CVE-2024-3472 to force a logged-in admin to delete modals without their consent.