CVE-2024-6719

HIGH

Offload Videos <1.0.1 - CSRF

Title source: llm

Description

The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack

Scores

CVSS v3 8.1
EPSS 0.0008
EPSS Percentile 24.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Classification

CWE
CWE-352
Status published

Affected Products (1)

webgarh/offload_videos < 1.0.1

Timeline

Published May 15, 2025
Tracked Since Feb 18, 2026