CVE-2024-35635: WordPress Ninja Tables plugin <= 5.0.9 - Server Side Request Forgery (SSRF) vulnerability
Published Jun 3, 2024
·Updated
Server-Side Request Forgery (SSRF) vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through 5.0.9.
Affected Software
3 affected components
WPManageNinja Ninja Tables<=5.0.9
WordPress Ninja Tables<=5.0.9
WPManageNinja Ninja Tables Wordpress<5.0.10
Remediation
Information
Update to 5.0.10 or a higher version.
Event History
Jun 3, 2024
CVE Published
via MITRE·10:03 AM
Data Sourced
via MITRE·10:03 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35635?
CVE-2024-35635 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
2
How do I fix CVE-2024-35635?
To fix CVE-2024-35635, update Ninja Tables to the latest version beyond 5.0.9.
3
What versions are affected by CVE-2024-35635?
CVE-2024-35635 affects Ninja Tables versions from n/a through 5.0.9.
4
What are the risks associated with CVE-2024-35635?
CVE-2024-35635 can allow attackers to send unauthorized requests from the server, potentially exposing sensitive information.
5
Is CVE-2024-35635 exploitable without authentication?
Yes, CVE-2024-35635 can often be exploited without authentication, making it particularly dangerous.