Cross-Site Request Forgery Vulnerability in Wow-Company Herd Effects
CVE-2025-24716

5.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
24 January 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Wow-Company Herd Effects product. This flaw enables an attacker to exploit user sessions and make unintended requests that could lead to unauthorized settings changes. Affected versions include all versions up to and including 6.2.1, which leaves users susceptible to potential security breaches. Users are encouraged to assess their security measures and implement necessary patches or updates.

Affected Version(s)

Herd Effects <= 6.2.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khang Duong (Patchstack Alliance)
.