CVE-2024-35633: WordPress Blocksy Companion plugin <= 2.0.42 - Server Side Request Forgery (SSRF) vulnerability
Published Jun 3, 2024
·Updated
Server-Side Request Forgery (SSRF) vulnerability in Creative Themes Blocksy Companion blocksy-companion.This issue affects Blocksy Companion: from n/a through <= 2.0.42.
Affected Software
3 affected components
creativethemes Blocksy Companion Wordpress<2.0.43
CreativeThemes Blocksy Companion<=2.0.42
WordPress Blocksy Companion<=2.0.42
Remediation
Information
Update to 2.0.43 or a higher version.
Event History
Jun 3, 2024
CVE Published
via MITRE·10:04 AM
Data Sourced
via MITRE·10:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35633?
CVE-2024-35633 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
2
How do I fix CVE-2024-35633?
To fix CVE-2024-35633, update the Blocksy Companion plugin to version 2.0.43 or later.
3
Which versions of Blocksy Companion are affected by CVE-2024-35633?
CVE-2024-35633 affects Blocksy Companion versions prior to 2.0.43.
4
What implications does CVE-2024-35633 have for users?
Exploitation of CVE-2024-35633 allows an attacker to send unauthorized requests from the server.
5
Is there a workaround for CVE-2024-35633?
Currently, the best approach is to update the plugin as there are no effective workarounds for CVE-2024-35633.