CVE-2024-31113: WordPress Easy Digital Downloads plugin <= 3.2.11 - Cross Site Request Forgery (CSRF) vulnerability
Published May 10, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.
Affected Software
3 affected components
Sandhillsdev Easy Digital Downloads Wordpress<3.2.12
Easy Digital Downloads Easy Digital Downloads<=3.2.11
WordPress Easy Digital Downloads<=3.2.11
Remediation
Information
Update to 3.2.12 or a higher version.
Event History
May 10, 2024
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
RemedyDescriptionSeverityWeakness
May 14, 2024
Data Sourced
via NVD·03:24 PM
DescriptionSeverityWeaknessAffected Software
Feb 22, 57075
Event
via NVD·07:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-31113?
CVE-2024-31113 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can potentially allow an attacker to manipulate user actions.
2
How do I fix CVE-2024-31113?
To fix CVE-2024-31113, update Easy Digital Downloads to version 3.2.12 or later.
3
Which versions of Easy Digital Downloads are affected by CVE-2024-31113?
CVE-2024-31113 affects Easy Digital Downloads versions from n/a through 3.2.11.
4
What is the nature of the vulnerability in CVE-2024-31113?
CVE-2024-31113 is a Cross-Site Request Forgery (CSRF) vulnerability that could allow unauthorized actions to be performed on behalf of an authenticated user.
5
Who is the vendor of the software affected by CVE-2024-31113?
The vendor of the software affected by CVE-2024-31113 is Sandhills Development, the developer of Easy Digital Downloads.