CVE-2024-24872: WordPress Themify Builder Plugin <= 7.0.5 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in Themify Themify Builder.This issue affects Themify Builder: from n/a through 7.0.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Themify Builder (WordPress plugin)to a version that resolves this vulnerability.Fixed in 7.0.6
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24872?
CVE-2024-24872 is classified as a Cross-Site Request Forgery (CSRF) vulnerability affecting Themify Builder versions up to 7.0.5.
How do I fix CVE-2024-24872?
To fix CVE-2024-24872, you should update Themify Builder to the latest version released after 7.0.5.
What versions of Themify Builder are affected by CVE-2024-24872?
CVE-2024-24872 affects Themify Builder versions from n/a up to and including 7.0.5.
What is Cross-Site Request Forgery in relation to CVE-2024-24872?
In relation to CVE-2024-24872, Cross-Site Request Forgery is a vulnerability that allows an attacker to trick users into submitting requests without their consent.
Is the Themify Builder Plugin for WordPress also affected by CVE-2024-24872?
Yes, the WordPress Themify Builder Plugin is affected by CVE-2024-24872 for versions up to and including 7.0.5.