CVE-2024-34814: WordPress Unyson plugin <=2.7.29 - Cross Site Request Forgery (CSRF) vulnerability
Published May 10, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Unyson Unyson unyson.This issue affects Unyson: from n/a through <= 2.7.29.
Affected Software
3 affected components
ThemeFuse Unyson<=2.7.29
WordPress Unyson plugin<=2.7.29
Brizy Unyson Wordpress<2.7.31
Remediation
Information
Update to 2.7.31 or a higher version.
Event History
May 10, 2024
CVE Published
via MITRE·08:38 AM
Data Sourced
via MITRE·08:38 AM
DescriptionSeverityWeakness
May 14, 2024
Data Sourced
via NVD·03:39 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34814?
The severity of CVE-2024-34814 is considered high due to its potential to allow unauthorized actions on behalf of users.
2
How do I fix CVE-2024-34814?
To fix CVE-2024-34814, update the Unyson plugin to version 2.7.30 or later where the vulnerability is patched.
3
Who is affected by CVE-2024-34814?
CVE-2024-34814 affects users of ThemeFuse Unyson versions up to and including 2.7.29.
4
What type of vulnerability is CVE-2024-34814?
CVE-2024-34814 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
What impact can CVE-2024-34814 have on my website?
The impact of CVE-2024-34814 can include unauthorized actions being performed on behalf of users, potentially compromising user accounts.