CVE-2024-1849: WP Customer Reviews < 3.7.1 - Malicious Redirect via HTTP-EQUIV Injection
Published Apr 15, 2024
·Updated
The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users to redirect a page to a malicious URL
Affected Software
2 affected components
Gowebsolutions Wp Customer Reviews Wordpress<3.7.1
WP Customer Reviews WP Customer Reviews<3.7.1
Event History
Apr 15, 2024
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-1849?
CVE-2024-1849 is considered a medium severity vulnerability due to its ability to redirect users to malicious URLs.
2
How do I fix CVE-2024-1849?
To fix CVE-2024-1849, upgrade the WP Customer Reviews plugin to version 3.7.1 or later.
3
Who is affected by CVE-2024-1849?
CVE-2024-1849 affects users with contributor and above roles on websites using WP Customer Reviews plugin versions prior to 3.7.1.
4
What can happen if CVE-2024-1849 is exploited?
Exploitation of CVE-2024-1849 can lead to unauthorized redirection of users to malicious URLs, potentially compromising user data.
5
Is there a patch for CVE-2024-1849?
Yes, the patch for CVE-2024-1849 is included in WP Customer Reviews version 3.7.1.