CVE-2024-51647
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2024-51647 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Chaser324 Featured Posts Scroll plugin. This issue permits an attacker to perform Stored XSS (Cross-Site Scripting) attacks on unsuspecting users. The vulnerability exists in the plugin versions from n/a to 1.25, and attackers can exploit it by crafting malicious requests that, when processed by the affected plugin, inject and execute malicious scripts in the browser of the targeted user. Successful exploitation can lead to unauthorized access to sensitive information, session hijacking, or other forms of security breaches. Users are advised to upgrade their plugin to the latest version as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.