CVE-2024-32107: WordPress Finale Lite plugin <= 2.18.0 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 11, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.
Affected Software
3 affected components
XLPlugins Finale Lite
WordPress Finale Lite<=2.18.0
XLPlugins Finale Wordpress<2.18.1
Remediation
Information
Update to 2.18.1 or a higher version.
Event History
Apr 11, 2024
CVE Published
via MITRE·12:59 PM
Data Sourced
via MITRE·12:59 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32107?
CVE-2024-32107 is categorized as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-32107?
To mitigate CVE-2024-32107, ensure that you update XLPlugins Finale Lite to the latest version above 2.18.0.
3
Which software is affected by CVE-2024-32107?
CVE-2024-32107 affects XLPlugins Finale Lite versions from n/a to 2.18.0.
4
What are the potential impacts of CVE-2024-32107?
CVE-2024-32107 could allow attackers to perform actions on behalf of users without their consent.
5
When was CVE-2024-32107 reported?
CVE-2024-32107 was reported for XLPlugins Finale Lite with no specific disclosure date mentioned.