Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerability in WP GoToWebinar
CVE-2024-38776
7.1HIGH
What is CVE-2024-38776?
A Cross-Site Request Forgery (CSRF) vulnerability in the Martin Gibson WP GoToWebinar plugin could allow attackers to exploit this weakness, leading to unauthorized actions be performed on behalf of an authenticated user. This issue particularly affects versions from n/a to 15.7, potentially enabling Cross-Site Scripting (XSS) attacks that compromise the security of WordPress sites.
Affected Version(s)
WP GoToWebinar <= 15.7