CVE-2024-32104: WordPress NextMove Lite plugin <= 2.18.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 15, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.18.1.
Affected Software
3 affected components
XLPlugins NextMove Lite<=2.18.1
WordPress NextMove Lite<=2.18.1
XLPlugins Nextmove Wordpress<2.18.2
Remediation
Information
Update to 2.18.2 or a higher version.
Event History
Apr 15, 2024
CVE Published
via MITRE·08:43 AM
Data Sourced
via MITRE·08:43 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32104?
CVE-2024-32104 is a moderate severity Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins NextMove Lite.
2
How do I fix CVE-2024-32104?
To fix CVE-2024-32104, upgrade the XLPlugins NextMove Lite plugin to version 2.18.2 or higher.
3
Which versions of NextMove Lite are affected by CVE-2024-32104?
CVE-2024-32104 affects all versions of NextMove Lite up to and including 2.18.1.
4
What type of vulnerability is CVE-2024-32104?
CVE-2024-32104 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Is CVE-2024-32104 specific to any platforms?
CVE-2024-32104 is specific to the XLPlugins NextMove Lite plugin used in WordPress.