CVE-2024-34817: WordPress Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.2.0 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.2.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34817?
CVE-2024-34817 has been classified as a medium-severity Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2024-34817?
To fix CVE-2024-34817, update the CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elementor, or Ninja Forms to the latest version above 1.2.0.
Which applications are affected by CVE-2024-34817?
CVE-2024-34817 affects CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elementor, and Ninja Forms versions up to 1.2.0.
Is there a workaround for CVE-2024-34817?
There is no documented workaround for CVE-2024-34817; updating to a secure version is the recommended approach.
What types of attacks are possible due to CVE-2024-34817?
CVE-2024-34817 may be exploited to perform unauthorized actions on behalf of an authenticated user, which could lead to data compromise.