CVE-2024-32450: WordPress WpTravelly plugin <= 1.6.0 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 15, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team WpTravelly.This issue affects WpTravelly: from n/a through 1.6.0.
Affected Software
1 affected component
MagePeople WpTravelly<=1.6.0
Remediation
Information
Update to 1.6.1 or a higher version.
Event History
Apr 15, 2024
CVE Published
via MITRE·07:52 AM
Data Sourced
via MITRE·07:52 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-32450?
CVE-2024-32450 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-32450?
To fix CVE-2024-32450, users should update the WpTravelly plugin to the latest version beyond 1.6.0.
3
What versions are affected by CVE-2024-32450?
CVE-2024-32450 affects WpTravelly plugin versions up to and including 1.6.0.
4
Who is the vendor of the product affected by CVE-2024-32450?
The vendor of the product affected by CVE-2024-32450 is MagePeople Team.
5
What types of attacks can exploit CVE-2024-32450?
CVE-2024-32450 can be exploited to perform unauthorized actions on behalf of authenticated users through CSRF attacks.