CVE-2024-32437: WordPress eCommerce Product Catalog plugin <= 3.3.28 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 15, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in impleCode eCommerce Product Catalog.This issue affects eCommerce Product Catalog: from n/a through 3.3.28.
Affected Software
1 affected component
impleCode eCommerce Product Catalog<=3.3.28
Remediation
Information
Update to 3.3.29 or a higher version.
Event History
Apr 15, 2024
CVE Published
via MITRE·08:07 AM
Data Sourced
via MITRE·08:07 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-32437?
CVE-2024-32437 is classified as a Cross-Site Request Forgery (CSRF) vulnerability with moderate severity.
2
How do I fix CVE-2024-32437?
To fix CVE-2024-32437, update the eCommerce Product Catalog to version 3.3.29 or later.
3
What versions are affected by CVE-2024-32437?
CVE-2024-32437 affects eCommerce Product Catalog versions up to and including 3.3.28.
4
What type of vulnerability is CVE-2024-32437?
CVE-2024-32437 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Who is the vendor of the affected software for CVE-2024-32437?
The vendor of the affected software for CVE-2024-32437 is impleCode.