CVE-2024-30456: WordPress WPCS – WordPress Currency Switcher Professional plugin <=1.2.0.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Mar 29, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1.
Affected Software
2 affected components
realmag777 WordPress Currency Switcher Professional (WPCS)<=1.2.0.1
Pluginus Wordpress Currency Switcher Wordpress<1.2.0.2
Remediation
Information
Update to 1.2.0.2 or a higher version.
Event History
Mar 29, 2024
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30456?
CVE-2024-30456 is classified as a Cross-Site Request Forgery (CSRF) vulnerability which can lead to unauthorized actions being performed on behalf of a user.
2
How do I fix CVE-2024-30456?
To fix CVE-2024-30456, update the WPCS plugin to version 1.2.0.2 or later.
3
What versions of WPCS are affected by CVE-2024-30456?
CVE-2024-30456 affects WPCS versions up to and including 1.2.0.1.
4
What types of attacks can CVE-2024-30456 facilitate?
CVE-2024-30456 can facilitate unauthorized actions through CSRF attacks, potentially compromising user accounts.
5
Is it safe to use WPCS version 1.2.0.1 after the disclosure of CVE-2024-30456?
Using WPCS version 1.2.0.1 is not safe after the disclosure of CVE-2024-30456 due to the identified CSRF vulnerability.