First published: Mon Apr 15 2024(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in E2Pdf.This issue affects e2pdf: from n/a through 1.20.27.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
E2Pdf | <=1.20.27 | |
E2Pdf | <=1.20.27 |
Update to 1.23.00 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-31373 is considered high due to its ability to allow unauthorized actions via Cross-Site Request Forgery.
To fix CVE-2024-31373, you should update the E2Pdf plugin to version 1.20.28 or later immediately.
CVE-2024-31373 affects E2Pdf versions up to and including 1.20.27 and the E2Pdf plugin for WordPress.
In the context of CVE-2024-31373, CSRF allows an attacker to perform actions on behalf of a victim user without their consent.
Users of E2Pdf should immediately update their plugin to the latest version to mitigate the risk associated with CVE-2024-31373.