PT-2024-37820 · WordPress · The Light Poll

Published

2024-08-06

·

Updated

2024-10-28

·

CVE-2024-6720

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Light Poll WordPress plugin version 1.0.0
Description The issue concerns the lack of CSRF checks in certain areas, potentially allowing attackers to trick logged-in users into performing unintended actions through CSRF attacks.
Recommendations For The Light Poll WordPress plugin version 1.0.0, consider updating to a version that includes CSRF checks to prevent unwanted actions. As a temporary workaround, restrict access to sensitive areas of the plugin to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-6720

Affected Products

The Light Poll