CVE-2024-37518
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-37518 refers to a Cross-Site Request Forgery (CSRF) vulnerability identified in The Events Calendar plugin. This issue enables an attacker to submit unauthorized requests on behalf of a user who is currently authenticated on a targeted website. The Events Calendar, a popular WordPress plugin, is affected from versions n/a through 6.5.1.4. Successful exploitation of this CSRF vulnerability can result in various malicious actions, including account takeover, data modification, or unauthorized access. Users are advised to update to the latest available version of The Events Calendar to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.