CVE-2025-24711: WordPress Popup Box Plugin <= 3.2.4 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Popup Box popup-box allows Cross Site Request Forgery.This issue affects Popup Box: from n/a through <= 3.2.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24711?
The severity of CVE-2025-24711 is classified as a Cross-Site Request Forgery (CSRF) vulnerability affecting Popup Box versions up to 3.2.4.
How do I fix CVE-2025-24711?
To fix CVE-2025-24711, update the Wow-Company Popup Box to the latest version beyond 3.2.4 to eliminate the CSRF vulnerability.
What is affected by CVE-2025-24711?
CVE-2025-24711 affects the Wow-Company Popup Box and the WordPress Popup Box Plugin up to version 3.2.4.
Can CVE-2025-24711 be exploited remotely?
Yes, CVE-2025-24711 can be exploited remotely through CSRF attacks if the vulnerability is not mitigated.
Is there a patch available for CVE-2025-24711?
Yes, a patch is available by updating the software to a version higher than 3.2.4 to resolve the CSRF vulnerability.