CVE-2024-24887: WordPress Contest Gallery Plugin <= 21.2.8.4 is vulnerable to Cross Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress.This issue affects Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress: from n/a through 21.2.8.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPressto a version that resolves this vulnerability.Fixed in 21.2.9
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24887?
The severity of CVE-2024-24887 is classified as moderate due to its nature as a Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2024-24887?
To fix CVE-2024-24887, update the Contest Gallery plugin to version 21.2.9 or later.
Which versions of the Contest Gallery plugin are affected by CVE-2024-24887?
CVE-2024-24887 affects versions of the Contest Gallery plugin prior to 21.2.9.
What type of vulnerability is CVE-2024-24887?
CVE-2024-24887 is a Cross-Site Request Forgery (CSRF) vulnerability that allows unauthorized actions to be performed on behalf of users.
Is CVE-2024-24887 remotely exploitable?
Yes, CVE-2024-24887 is remotely exploitable, which means that attackers can leverage this vulnerability over the internet.