CVE-2024-34756: WordPress Integration for HubSpot and Contact Form 7 plugin <= 1.3.1 - Cross Site Request Forgery (CSRF) vulnerability
Published May 17, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 HubSpot.This issue affects Integration for Contact Form 7 HubSpot: from n/a through 1.3.1.
Affected Software
2 affected components
CRM Perks Integration for Contact Form 7 HubSpot<=1.3.1
WordPress Integration for HubSpot and Contact Form 7<=1.3.1
Remediation
Information
Update to 1.3.2 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·09:49 AM
Data Sourced
via MITRE·09:49 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34756?
CVE-2024-34756 is identified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How does CVE-2024-34756 impact users of CRM Perks Integration for Contact Form 7 HubSpot?
The vulnerability can allow attackers to perform unauthorized actions on behalf of users without their consent.
3
Which version of CRM Perks Integration for Contact Form 7 HubSpot is affected by CVE-2024-34756?
CVE-2024-34756 affects versions of CRM Perks Integration for Contact Form 7 HubSpot up to and including 1.3.1.
4
How do I fix CVE-2024-34756?
To remediate CVE-2024-34756, upgrade to a patched version of CRM Perks Integration for Contact Form 7 HubSpot that addresses the vulnerability.
5
Are there any recommended actions for users still using affected versions of CRM Perks Integration for Contact Form 7 HubSpot due to CVE-2024-34756?
Users should immediately update their plugin to ensure they are no longer vulnerable to the CSRF attack vector.