CVE-2024-31362: WordPress ProfileGrid – User Profiles, Memberships, Groups and Communities plugin <= 5.7.8 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 12, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.
Affected Software
3 affected components
Metagauss Profilegrid Wordpress<5.7.9
Metagauss ProfileGrid<=5.7.8
WordPress ProfileGrid<=5.7.8
Remediation
Information
Update to 5.7.9 or a higher version.
Event History
Apr 12, 2024
CVE Published
via MITRE·12:22 PM
Data Sourced
via MITRE·12:22 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31362?
CVE-2024-31362 is classified as a Cross-Site Request Forgery (CSRF) vulnerability which can allow unauthorized actions to be performed on behalf of authenticated users.
2
How do I fix CVE-2024-31362?
To fix CVE-2024-31362, update Metagauss ProfileGrid to version 5.7.9 or later.
3
Which versions of ProfileGrid are affected by CVE-2024-31362?
CVE-2024-31362 affects Metagauss ProfileGrid versions from n/a up to and including 5.7.8.
4
What kind of attack does CVE-2024-31362 enable?
CVE-2024-31362 enables attackers to execute unauthorized commands on the application, compromising user accounts.
5
Is CVE-2024-31362 a common vulnerability?
CSRF vulnerabilities like CVE-2024-31362 are relatively common and can be critical if not properly mitigated.