CVE-2024-2951: WordPress RegistrationMagic plugin <= 5.3.0.0 - Cross Site Request Forgery (CSRF) vulnerability
Published Mar 26, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.3.0.0.
Affected Software
3 affected components
Metagauss Registrationmagic Wordpress<5.3.1.0
Metagauss RegistrationMagic>=5.3.0.0
RegistrationMagic<=5.3.0.0
Remediation
Information
Update to 5.3.1.0 or a higher version.
Event History
Mar 26, 2024
CVE Published
via MITRE·06:03 PM
Data Sourced
via MITRE·06:03 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-2951?
CVE-2024-2951 has been classified as a high severity Cross-Site Request Forgery vulnerability.
2
How do I fix CVE-2024-2951?
To fix CVE-2024-2951, upgrade Metagauss RegistrationMagic to the latest version available beyond 5.3.0.0.
3
Which versions of RegistrationMagic are affected by CVE-2024-2951?
CVE-2024-2951 affects all versions of RegistrationMagic from n/a up to and including 5.3.0.0.
4
What is a Cross-Site Request Forgery vulnerability like CVE-2024-2951?
A Cross-Site Request Forgery vulnerability allows an attacker to perform actions on behalf of a user without their consent.
5
Who is the vendor affected by CVE-2024-2951?
The vendor affected by CVE-2024-2951 is Metagauss, specifically for their RegistrationMagic plugin.