CVE-2024-3629: DACHANDE663 Hl Twitter
Low severity, CVSS 2.4. EPSS: 0.2% chance of exploitation in the next 30 days.
The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected products
- DACHANDE663 Hl Twitter: up to and including 2014.1.18
Published 2024-05-15. Last modified 2026-06-17.