CVE-2024-34802
Wpfoxly
CVE-2024-34802 is a critical authorization vulnerability found in the AdFoxly WordPress plugin, specifically affecting versions up to 1.8.5. This missing authorization flaw allows unauthorized access and manipulation of the plugin's settings. While the CVSS score is a high 9.8, SOCRadar's Vulnerability Risk Score (SVRS) is 34, suggesting a lower real-world risk than indicated by the CVSS alone. Despite the lower SVRS, the presence of "In The Wild" tags indicates active exploitation. This poses a significant risk, potentially enabling attackers to inject malicious ads, modify website content, or compromise the entire WordPress site. Immediate investigation is warranted to determine the extent of potential damage and implement necessary security measures. Users of AdFoxly should update to the latest version or apply appropriate mitigations to address this vulnerability.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.