CSRF Vulnerability in Wow-Company Counter Box Plugin
CVE-2025-24715
5.4MEDIUM
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Wow-Company Counter Box plugin, allowing attackers to potentially change settings on behalf of users without their consent. This issue affects versions from n/a to 2.0.5, posing a risk to user accounts and data integrity. Implementing proper CSRF token checks and ensuring software is up to date can help mitigate the risk associated with this vulnerability.
Affected Version(s)
Counter Box <= 2.0.5
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Khang Duong (Patchstack Alliance)