CVE-2024-37238

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 352

Summary

CVE-2024-37238: A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the WPAdverts – Classifieds Plugin, affecting versions from n/a to 2.1.2. An attacker can exploit this issue to perform unintended actions on a user's account, such as posting ads or modifying settings, by tricking them into clicking a malicious link. The user must be logged in to the affected WordPress site for the attack to succeed. To mitigate this risk, it is recommended that users update the WPAdverts plugin to the latest version as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share