First published: Fri May 10 2024(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.2.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CRM Perks Integration for Pipedrive and Contact Form 7 | <=1.2.0 | |
Softlabbd Upload Fields For Wpforms Wordpress | <=1.2.0 | |
Elementor | <=1.2.0 | |
Ninja Forms | <=1.2.0 |
Update to 1.2.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34817 has been classified as a medium-severity Cross-Site Request Forgery (CSRF) vulnerability.
To fix CVE-2024-34817, update the CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elementor, or Ninja Forms to the latest version above 1.2.0.
CVE-2024-34817 affects CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elementor, and Ninja Forms versions up to 1.2.0.
There is no documented workaround for CVE-2024-34817; updating to a secure version is the recommended approach.
CVE-2024-34817 may be exploited to perform unauthorized actions on behalf of an authenticated user, which could lead to data compromise.