Description
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forgery.This issue affects Modal Window: from n/a through <= 6.1.4.
Published: 2025-01-24
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WordPress users running Wow‑Company Modal Window plugin version 6.1.4 or earlier are susceptible to a Cross‑Site Request Forgery vulnerability that permits an attacker to modify plugin settings without the victim’s knowledge. The flaw exists because the plugin accepts state‑changing requests without verifying that the request originates from an authenticated and authorizing source. If successfully triggered, an attacker could change display options, enable or disable features, or alter any configuration parameters stored by the plugin. Such changes could lead to degraded functionality, user experience disruption, or indirect security weaknesses by enabling the plugin’s other features to function with unintended settings.

Affected Systems

Affected systems include installations of the Wow‑Company Modal Window WordPress plugin, with versions up to and including 6.1.4. The vulnerability is present across all WordPress environments that have the plugin activated, regardless of the site’s role or content. The component is distributed as a WordPress plugin under the vendor name Wow‑Company and identified in the National Vulnerability Database by the CPE string cpe:2.3:a:wow-company:modal_window:*:*:*:*:*:wordpress:*:*,

Risk and Exploitability

Given the CVSS score of 5.4, the vulnerability presents a moderate risk. Exploitation requires the attacker to target a user who is logged into the WordPress site and has permission to modify Modal Window settings. The EPSS score of less than 1% suggests that the vulnerability is unlikely to be actively exploited in the wild. This entry is not in the CISA KEV catalog. It is inferred that the attacker would leverage a malicious web site or email to trick a privileged user into submitting a CSRF request that alters the plugin configuration.

Generated by OpenCVE AI on May 1, 2026 at 18:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Wow‑Company Modal Window plugin to version 6.1.5 or newer, where CSRF protection has been added.
  • Restrict access to the plugin’s settings page so that only administrators can modify configurations and enforce HTTP authentication on the settings endpoint where possible.
  • Implement a web application firewall rule that blocks POST requests to the plugin’s settings endpoint unless a valid CSRF token is present.

Generated by OpenCVE AI on May 1, 2026 at 18:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3909 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window allows Cross Site Request Forgery. This issue affects Modal Window: from n/a through 6.1.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window allows Cross Site Request Forgery. This issue affects Modal Window: from n/a through 6.1.4. Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forgery.This issue affects Modal Window: from n/a through <= 6.1.4.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 03 Jul 2025 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Wow-company
Wow-company modal Window
CPEs cpe:2.3:a:wow-company:modal_window:*:*:*:*:*:wordpress:*:*
Vendors & Products Wow-company
Wow-company modal Window

Fri, 24 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window allows Cross Site Request Forgery. This issue affects Modal Window: from n/a through 6.1.4.
Title WordPress Modal Window Plugin <= 6.1.4 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

Wow-company Modal Window
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:32.976Z

Reserved: 2025-01-23T14:52:38.447Z

Link: CVE-2025-24717

cve-icon Vulnrichment

Updated: 2025-01-24T18:37:46.752Z

cve-icon NVD

Status : Modified

Published: 2025-01-24T18:15:45.210

Modified: 2026-04-23T15:25:21.497

Link: CVE-2025-24717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T18:45:15Z

Weaknesses