CVE-2024-32440: WordPress Asgaros Forum plugin <= 2.8.0 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 15, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.8.0.
Affected Software
3 affected components
Asgaros Asgaros Forum WordPress<2.9.0
Thomas Belser Asgaros Forum<=2.8.0
WordPress Asgaros Forum plugin<=2.8.0
Remediation
Information
Update to 2.9.0 or a higher version.
Event History
Apr 15, 2024
CVE Published
via MITRE·08:04 AM
Data Sourced
via MITRE·08:04 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-32440?
CVE-2024-32440 is categorized as a critical vulnerability due to the potential for unauthorized actions on behalf of users.
2
How do I fix CVE-2024-32440?
To resolve CVE-2024-32440, update Asgaros Forum to version 2.9.0 or later.
3
What software is affected by CVE-2024-32440?
CVE-2024-32440 affects Asgaros Forum versions from n/a to 2.8.0.
4
What type of vulnerability is CVE-2024-32440?
CVE-2024-32440 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Who is the vendor for the affected software in CVE-2024-32440?
The vendor for the affected software in CVE-2024-32440 is Thomas Belser.