CVE-2024-22136
Droitthemes
CVE-2024-22136 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Droit Elementor Addons plugin. This flaw allows attackers to potentially execute unauthorized actions on behalf of authenticated users.
CVE-2024-22136 impacts versions up to 3.1.5 of the Droit Elementor Addons plugin, a widely used WordPress plugin. An attacker could exploit this by tricking a logged-in user into clicking a malicious link, leading to unintended actions on the user's account. Although the CVSS score is 8.8, indicating high severity, the SOCRadar Vulnerability Risk Score (SVRS) of 77 suggests that while serious, it is not in the most critical category requiring immediate action. The vulnerability is categorized as CWE-352, a common type of web security flaw. This poses a risk of unauthorized modifications or data breaches on affected WordPress sites. Site administrators should update the plugin to a patched version as soon as possible to mitigate this risk.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.