CVE-2024-37235: WordPress Groundhogg plugin <= 3.4.2.3 - Cross Site Request Forgery (CSRF) vulnerability
Published Jan 2, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Adrian Tobey Groundhogg groundhogg allows Cross Site Request Forgery.This issue affects Groundhogg: from n/a through <= 3.4.2.3.
Affected Software
3 affected components
Groundhogg Groundhogg<=3.4.2.3
WordPress Groundhogg plugin<=3.4.2.3
Groundhogg Groundhogg WordPress<3.4.3
Remediation
Information
Update the WordPress Groundhogg plugin to the latest available version (at least 3.4.3).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37235?
CVE-2024-37235 is classified as a Cross-Site Request Forgery (CSRF) vulnerability which can be severe depending on the impact of unauthorized actions.
2
How do I fix CVE-2024-37235?
To fix CVE-2024-37235, update the Groundhogg plugin to the latest version that addresses the CSRF vulnerability.
3
Who is affected by CVE-2024-37235?
CVE-2024-37235 affects users of Groundhogg versions up to and including 3.4.2.3.
4
What can attackers do with CVE-2024-37235?
Attackers can exploit CVE-2024-37235 to perform unauthorized actions on behalf of logged-in users without their consent.
5
Is CVE-2024-37235 specific to certain software versions?
Yes, CVE-2024-37235 specifically affects Groundhogg up to version 3.4.2.3.