CVE-2025-24717: WordPress Modal Window Plugin <= 6.1.4 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forgery.This issue affects Modal Window: from n/a through <= 6.1.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24717?
CVE-2025-24717 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-24717?
To fix CVE-2025-24717, users should update the Wow-Company Modal Window or WordPress Modal Window Plugin to version 6.1.5 or later.
What versions of the software are affected by CVE-2025-24717?
CVE-2025-24717 affects Wow-Company Modal Window and WordPress Modal Window Plugin versions up to and including 6.1.4.
What types of attacks can CVE-2025-24717 support?
CVE-2025-24717 can be exploited to perform unauthorized actions on behalf of users due to its CSRF nature.
Who is impacted by CVE-2025-24717?
Any user of the Wow-Company Modal Window or WordPress Modal Window Plugin who has not updated to the patched version is potentially impacted by CVE-2025-24717.