CVE-2024-37448

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 352

Summary

CVE-2024-37448 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the OnePress plugin, versions n/a through 2.3.6. An attacker can exploit this issue by tricking a user into performing unwanted actions on a targeted website. As a result, the attacker can make unauthorized changes, such as modifying the user's account settings or making unintended purchases, without the user's consent. To mitigate this risk, it is recommended that users update to the latest version of OnePress, which contains a patch for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share