CVE-2024-38766: WordPress Matomo Analytics plugin <= 5.1.1 - Cross Site Request Forgery (CSRF) leading to Notice Dismissal vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in matomoteam Matomo Analytics matomo allows Cross Site Request Forgery.This issue affects Matomo Analytics: from n/a through <= 5.1.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38766?
CVE-2024-38766 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that could allow unauthorized actions in Matomo Analytics.
How do I fix CVE-2024-38766?
To mitigate CVE-2024-38766, update Matomo Analytics to a version later than 5.1.1 or implement CSRF protections in your application.
Who is affected by CVE-2024-38766?
CVE-2024-38766 affects users of Matomo Analytics from n/a up to version 5.1.1 and the Matomo Analytics WordPress plugin up to version 5.1.1.
What are the potential impacts of CVE-2024-38766?
Exploitation of CVE-2024-38766 could lead to unauthorized actions performed on behalf of a user, which may compromise the integrity of the application.
Is CVE-2024-38766 applicable to all versions of Matomo Analytics?
No, CVE-2024-38766 specifically affects versions from n/a through 5.1.1 of Matomo Analytics.