CVE-2025-24623

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 24, 2025
CWE ID 352

Summary

CVE-2025-24623 is a Cross-Site Request Forgery (CSRF) vulnerability that affects Really Simple SSL, a popular WordPress plugin. This issue permits attackers to manipulate a user's session into making unintended actions. The vulnerability exists in versions from n/a to 9.1.4 of the plugin. Successful exploitation can lead to data modifications, unauthorized changes, or even complete account takeover. It is crucial for WordPress users using Really Simple SSL to update to the latest version and apply additional security measures, such as implementing CSRF tokens, to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share