CVE-2024-31235: WordPress Comments Import & Export plugin <= 2.3.5 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 12, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in WebToffee WordPress Comments Import & Export.This issue affects WordPress Comments Import & Export: from n/a through 2.3.5.
Affected Software
1 affected component
WebToffee WordPress Comments Import & Export<=2.3.5
Remediation
Information
Update to 2.3.6 or a higher version.
Event History
Apr 12, 2024
CVE Published
via MITRE·01:01 PM
Data Sourced
via MITRE·01:01 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31235?
CVE-2024-31235 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-31235?
To fix CVE-2024-31235, update the WebToffee WordPress Comments Import & Export plugin to version 2.3.6 or later.
3
Which versions are affected by CVE-2024-31235?
CVE-2024-31235 affects WebToffee WordPress Comments Import & Export versions prior to 2.3.6.
4
Can CVE-2024-31235 lead to unauthorized actions?
Yes, CVE-2024-31235 can allow attackers to perform unauthorized actions on behalf of users.
5
Is CVE-2024-31235 specific to any platform?
CVE-2024-31235 specifically affects the WebToffee WordPress Comments Import & Export plugin.