CVE-2024-31293: WordPress Easy Digital Downloads plugin <= 3.2.6 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 12, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.6.
Affected Software
3 affected components
Sandhillsdev Easy Digital Downloads Wordpress<3.2.7
Easy Digital Downloads Easy Digital Downloads<=3.2.6
WordPress Easy Digital Downloads plugin<=3.2.6
Remediation
Information
Update to 3.2.7 or a higher version.
Event History
Apr 12, 2024
CVE Published
via MITRE·12:34 PM
Data Sourced
via MITRE·12:34 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 21, 57075
Event
via NVD·07:19 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-31293?
CVE-2024-31293 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that can compromise user actions without their consent.
2
How do I fix CVE-2024-31293?
To fix CVE-2024-31293, update Easy Digital Downloads to version 3.2.7 or later.
3
Who is affected by CVE-2024-31293?
CVE-2024-31293 affects users of Easy Digital Downloads versions from n/a up to 3.2.6.
4
What type of vulnerability is CVE-2024-31293?
CVE-2024-31293 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2024-31293 lead to data breaches?
While CVE-2024-31293 does not directly lead to data breaches, it can allow unauthorized actions on behalf of users, potentially compromising their accounts.