CVE-2024-22140: WordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cozmoslabs Profile Builder Pro (WordPress Profile Builder Pro plugin)to a version that resolves this vulnerability.Fixed in 3.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22140?
CVE-2024-22140 is classified as a high severity Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2024-22140?
To fix CVE-2024-22140, update the Cozmoslabs Profile Builder Pro plugin to version 3.10.1 or higher.
Which versions of Profile Builder Pro are affected by CVE-2024-22140?
CVE-2024-22140 affects Profile Builder Pro versions up to and including 3.10.0.
What type of vulnerability is CVE-2024-22140?
CVE-2024-22140 is a Cross-Site Request Forgery (CSRF) vulnerability.
Can CVE-2024-22140 lead to account takeover?
Yes, CVE-2024-22140 can potentially lead to account takeover due to its CSRF nature.