CVE-2024-35684: WordPress ElasticPress plugin <= 5.1.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Jun 8, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in 10up ElasticPress elasticpress.This issue affects ElasticPress: from n/a through <= 5.1.1.
Affected Software
1 affected component
10up Elasticpress Wordpress<5.1.2
Remediation
Information
Update to 5.1.2 or a higher version.
Event History
Jun 8, 2024
CVE Published
via MITRE·02:53 PM
Data Sourced
via MITRE·02:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35684?
CVE-2024-35684 is rated as a moderate severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-35684?
To fix CVE-2024-35684, update the 10up ElasticPress plugin to version 5.1.2 or later.
3
What versions of ElasticPress are affected by CVE-2024-35684?
CVE-2024-35684 affects ElasticPress versions from n/a through 5.1.1.
4
What is a Cross-Site Request Forgery (CSRF) vulnerability in the context of CVE-2024-35684?
A Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to perform actions on behalf of a victim without their consent.
5
Who is the vendor for the vulnerability CVE-2024-35684?
The vendor for the vulnerability CVE-2024-35684 is 10up, which develops the ElasticPress plugin.