CVE-2024-34827: WordPress Translate Multilingual sites – TranslatePress plugin <= 2.7.5 - Cross Site Request Forgery (CSRF) vulnerability
Published May 10, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban TranslatePress.This issue affects TranslatePress: from n/a through 2.7.5.
Affected Software
1 affected component
Cozmoslabs TranslatePress<=2.7.5
Remediation
Information
Update to 2.7.6 or a higher version.
Event History
May 10, 2024
CVE Published
via MITRE·08:18 AM
Data Sourced
via MITRE·08:18 AM
RemedyDescriptionSeverityWeakness
May 14, 2024
Data Sourced
via NVD·03:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34827?
CVE-2024-34827 is classified as a Cross-Site Request Forgery (CSRF) vulnerability in TranslatePress.
2
How do I fix CVE-2024-34827?
To fix CVE-2024-34827, update TranslatePress to the latest version beyond 2.7.5.
3
Which versions of TranslatePress are affected by CVE-2024-34827?
CVE-2024-34827 affects TranslatePress versions up to and including 2.7.5.
4
What impact does CVE-2024-34827 have on my website?
CVE-2024-34827 allows attackers to perform actions on behalf of authenticated users without their consent.
5
Who is responsible for the CVE-2024-34827 vulnerability?
CVE-2024-34827 was discovered by Razvan Mocanu, Madalin Ungureanu, and Cristophor Hurduban.