CVE-2025-24716: WordPress Herd Effects Plugin <= 6.2.1 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Herd Effects mwp-herd-effect allows Cross Site Request Forgery.This issue affects Herd Effects: from n/a through <= 6.2.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24716?
CVE-2025-24716 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that can potentially allow unauthorized actions to be performed on behalf of a user.
How do I fix CVE-2025-24716?
To fix CVE-2025-24716, update Wow-Company Herd Effects or the WordPress Herd Effects Plugin to version 6.2.1 or later to mitigate the CSRF risks.
What software is affected by CVE-2025-24716?
CVE-2025-24716 affects Wow-Company Herd Effects versions up to 6.2.1 and the WordPress Herd Effects Plugin versions up to 6.2.1.
What are the potential impacts of CVE-2025-24716?
The potential impacts of CVE-2025-24716 include unauthorized changes to user settings and actions being taken without user consent.
Is there a known exploit for CVE-2025-24716?
There is no specific public knowledge of active exploits for CVE-2025-24716, but the CSRF vulnerability can enable attackers to exploit affected systems.