CVE-2024-35638: WordPress ActiveDEMAND plugin <= 0.2.43 - Cross Site Request Forgery (CSRF) vulnerability
Published Jun 3, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in JumpDEMAND Inc. ActiveDEMAND.This issue affects ActiveDEMAND: from n/a through 0.2.43.
Affected Software
2 affected components
JumpDEMAND ActiveDEMAND<0.2.43
WordPress ActiveDEMAND plugin<0.2.43
Event History
Jun 3, 2024
CVE Published
via MITRE·08:57 AM
Data Sourced
via MITRE·08:57 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35638?
The severity of CVE-2024-35638 is classified as high due to its potential for unauthorized actions on behalf of users.
2
How do I fix CVE-2024-35638?
To fix CVE-2024-35638, upgrade ActiveDEMAND to version 0.2.44 or later.
3
Which versions are affected by CVE-2024-35638?
CVE-2024-35638 affects ActiveDEMAND versions from n/a up to but not including 0.2.43.
4
Is the WordPress ActiveDEMAND plugin vulnerable to CVE-2024-35638?
Yes, the WordPress ActiveDEMAND plugin versions from n/a through 0.2.43 are vulnerable to CVE-2024-35638.
5
What type of vulnerability is CVE-2024-35638?
CVE-2024-35638 is a Cross-Site Request Forgery (CSRF) vulnerability.