CVE-2024-3478
CVE-2024-3478: A Cross-Site Request Forgery (CSRF) vulnerability exists in the Herd Effects WordPress plugin before version 5.2.7, potentially allowing attackers to force logged-in administrators to perform unintended actions. This security flaw stems from missing CSRF checks in specific bulk actions within the plugin. While the CVSS score is 6.1, indicating a medium severity, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting a lower immediate risk compared to more critical vulnerabilities. However, the presence of CWE-352 and "In The Wild" tag suggest the vulnerability is actively being exploited. Successful exploitation could lead to unauthorized deletion of effects or other administrative functions. Therefore, updating to version 5.2.7 or later is crucial to mitigate this risk. This vulnerability is significant because it can compromise the integrity and control of a WordPress site if left unpatched.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.