CVE-2024-35632: WordPress Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.1.5 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks. Integration for Contact Form 7 and Constant Contact.This issue affects Integration for Contact Form 7 and Constant Contact: from n/a through 1.1.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35632?
CVE-2024-35632 is classified as a Cross-Site Request Forgery (CSRF) vulnerability which can lead to unauthorized actions being performed on behalf of the user.
How do I fix CVE-2024-35632?
To fix CVE-2024-35632, update the Integration for Contact Form 7 and Constant Contact plugin to the latest version beyond 1.1.5.
What versions are affected by CVE-2024-35632?
CVE-2024-35632 affects versions up to and including 1.1.5 of the Integration for Contact Form 7 and Constant Contact plugin.
Who is affected by CVE-2024-35632?
Users of the CRM Perks Integration for Contact Form 7 and Constant Contact plugin, including WordPress users utilizing WPForms, Elementor, or Ninja Forms, are affected by CVE-2024-35632.
What type of vulnerability is CVE-2024-35632?
CVE-2024-35632 is a Cross-Site Request Forgery (CSRF) vulnerability that enables attackers to trick users into performing actions without their consent.