CVE-2024-32106: WordPress WP Compress plugin <= 6.10.35 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 11, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One].This issue affects WP Compress – Image Optimizer [All-In-One]: from n/a through 6.10.35.
Affected Software
3 affected components
WP Compress WP Compress – Image Optimizer<=6.10.35
WordPress WP Compress<=6.10.35
Wpcompress Wp Compress Wordpress<6.11.01
Remediation
Information
Update to 6.11.01 or a higher version.
Event History
Apr 11, 2024
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32106?
CVE-2024-32106 is classified as a cross-site request forgery (CSRF) vulnerability affecting multiple versions of WP Compress – Image Optimizer.
2
How do I fix CVE-2024-32106?
To mitigate CVE-2024-32106, users should update WP Compress – Image Optimizer to the latest version beyond 6.10.35.
3
What software is affected by CVE-2024-32106?
CVE-2024-32106 affects WP Compress – Image Optimizer versions up to and including 6.10.35.
4
What type of vulnerability is CVE-2024-32106?
CVE-2024-32106 is a cross-site request forgery (CSRF) vulnerability.
5
Is there any exploit details available for CVE-2024-32106?
Specific exploit details for CVE-2024-32106 are not provided in the current documentation.