CVE-2024-52421

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Nov 19, 2024
CWE ID 352

Summary

CVE-2024-52421 is a newly disclosed Cross-Site Request Forgery (CSRF) vulnerability that affects the WP Popup Window Maker plugin for WordPress. An attacker can exploit this issue to perform Stored Cross-Site Scripting (XSS) attacks against users. The vulnerability exists in versions of WP Popup Window Maker from n/a through 2.0, and successful exploitation could lead to the execution of malicious scripts in a user's browser. This could potentially result in unauthorized access or data theft. Users are urged to update their plugin to the latest version as soon as possible to mitigate the risk of this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share