CVE-2024-31936: WordPress UsersWP plugin < 1.2.6 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 11, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a before 1.2.6.
Affected Software
1 affected component
AyeCode UsersWP<1.2.6
Remediation
Information
Update to 1.2.6 or a higher version.
Event History
Apr 11, 2024
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31936?
CVE-2024-31936 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that can potentially allow attackers to perform actions on behalf of users without their consent.
2
How do I fix CVE-2024-31936?
To fix CVE-2024-31936, upgrade UsersWP to version 1.2.6 or later.
3
What versions of UsersWP are affected by CVE-2024-31936?
CVE-2024-31936 affects all versions of UsersWP prior to 1.2.6.
4
What kind of attacks can CVE-2024-31936 facilitate?
CVE-2024-31936 can facilitate unauthorized actions that may compromise user accounts and sensitive data.
5
Who is impacted by CVE-2024-31936?
All users of AyeCode Ltd UsersWP versions before 1.2.6 are impacted by CVE-2024-31936.