CVE-2025-24715: WordPress Counter Box Plugin <= 2.0.5 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Counter Box counter-box allows Cross Site Request Forgery.This issue affects Counter Box: from n/a through <= 2.0.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24715?
The severity of CVE-2025-24715 has not been officially rated, but Cross-Site Request Forgery (CSRF) vulnerabilities are generally considered critical due to their potential impact on user accounts and data.
How do I fix CVE-2025-24715?
To fix CVE-2025-24715, update the Wow-Company Counter Box to a version later than 2.0.5 or apply any available security patches.
What systems are affected by CVE-2025-24715?
CVE-2025-24715 affects Wow-Company Counter Box versions from n/a through 2.0.5, including the WordPress Counter Box Plugin.
What type of vulnerability is CVE-2025-24715?
CVE-2025-24715 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability, which allows unauthorized commands to be transmitted from a user that the web application trusts.
Can CVE-2025-24715 lead to data compromise?
Yes, CVE-2025-24715 can potentially lead to data compromise as it allows attackers to perform unauthorized actions on behalf of users.