CVE-2024-30454: WordPress WP SMS plugin <= 6.6.2 - Cross Site Request Forgery (CSRF) vulnerability
Published Mar 29, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2.
Affected Software
3 affected components
VeronaLabs Wp Sms Wordpress<6.6.3
VeronaLabs WP SMS<=6.6.2
WordPress WP SMS plugin<=6.6.2
Remediation
Information
Update to 6.6.3 or a higher version.
Event History
Mar 29, 2024
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30454?
CVE-2024-30454 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to unauthorized actions being performed on behalf of an authenticated user.
2
How do I fix CVE-2024-30454?
To fix CVE-2024-30454, update the VeronaLabs WP SMS plugin to the latest version beyond 6.6.2.
3
What versions are affected by CVE-2024-30454?
CVE-2024-30454 affects all versions of the VeronaLabs WP SMS plugin up to and including version 6.6.2.
4
What types of attacks can CVE-2024-30454 enable?
CVE-2024-30454 can enable attackers to perform unauthorized actions within a user's session, potentially compromising their account.
5
Who is impacted by CVE-2024-30454?
Users of the VeronaLabs WP SMS plugin running versions from n/a up to 6.6.2 are at risk due to CVE-2024-30454.