CVE-2024-43336: WordPress WP User Manager – User Profile Builder & Membership plugin <= 2.9.10 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in WP User Manager WP User Manager wp-user-manager.This issue affects WP User Manager: from n/a through <= 2.9.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43336?
CVE-2024-43336 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can allow unauthorized actions to be performed on behalf of authenticated users.
How do I fix CVE-2024-43336?
To fix CVE-2024-43336, ensure you update WP User Manager to the latest version, which addresses the CSRF vulnerability.
What versions of WP User Manager are affected by CVE-2024-43336?
CVE-2024-43336 affects all versions of WP User Manager from n/a up to and including version 2.9.10.
What are the potential impacts of exploiting CVE-2024-43336?
Exploitation of CVE-2024-43336 could allow an attacker to impersonate an authenticated user and perform unauthorized actions on a WordPress site.
Is there a patch available for CVE-2024-43336?
Yes, a patch is available by updating WP User Manager to a version later than 2.9.10 to mitigate CVE-2024-43336.