CVE-2024-31941: WordPress CP Media Player plugin <= 1.1.3 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Media Player.This issue affects CP Media Player: from n/a through 1.1.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31941?
CVE-2024-31941 is classified as a Cross-Site Request Forgery (CSRF) vulnerability with a potentially high impact due to its ability to exploit user actions without their consent.
How do I fix CVE-2024-31941?
To fix CVE-2024-31941, update the CodePeople CP Media Player to the latest version beyond 1.1.3, where the vulnerability is patched.
Which versions of CodePeople CP Media Player are affected by CVE-2024-31941?
CVE-2024-31941 affects all versions of CodePeople CP Media Player from its initial release up to and including version 1.1.3.
Is any configuration needed to mitigate CVE-2024-31941?
No specific configuration is needed; the best course of action is to upgrade to the patched version of the software.
What type of vulnerability is CVE-2024-31941?
CVE-2024-31941 is a Cross-Site Request Forgery (CSRF) vulnerability, which allows an attacker to perform unauthorized actions on behalf of an authenticated user.