CVE-2024-34809: WordPress EmpowerWP theme <= 1.0.21 - Cross Site Request Forgery (CSRF) vulnerability
Published May 17, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes EmpowerWP.This issue affects EmpowerWP: from n/a through 1.0.21.
Affected Software
3 affected components
Extend Themes EmpowerWP<=1.0.21
WordPress EmpowerWP<=1.0.21
ExtendThemes Empowerwp Wordpress<1.0.22
Remediation
Information
Update to 1.0.22 or a higher version.
Event History
May 17, 2024
CVE Published
via MITRE·09:43 AM
Data Sourced
via MITRE·09:43 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34809?
CVE-2024-34809 has been classified as a high-severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-34809?
To fix CVE-2024-34809, update EmpowerWP to a version higher than 1.0.21.
3
What versions of EmpowerWP are affected by CVE-2024-34809?
CVE-2024-34809 affects EmpowerWP versions from n/a up to and including 1.0.21.
4
What impact does CVE-2024-34809 have on users?
CVE-2024-34809 may allow attackers to perform actions on behalf of users without their consent.
5
Is there a known exploit for CVE-2024-34809?
As of now, there are no publicly disclosed exploits for CVE-2024-34809.