CVE-2024-43338: WordPress Crowdsignal Polls & Ratings plugin <= 3.1.3 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Automattic Crowdsignal Dashboard – Polls, Surveys & more polldaddy allows Cross Site Request Forgery.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through <= 3.1.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43338?
CVE-2024-43338 is classified as a Cross-Site Request Forgery (CSRF) vulnerability that can compromise user actions without their consent.
How do I fix CVE-2024-43338?
To fix CVE-2024-43338, ensure that you update the Crowdsignal Dashboard to version 3.1.3 or later.
Which products are affected by CVE-2024-43338?
CVE-2024-43338 affects Automattic Crowdsignal Dashboard and Crowdsignal Polls & Ratings versions up to and including 3.1.2.
What types of attacks can exploit CVE-2024-43338?
CVE-2024-43338 can be exploited through Cross-Site Request Forgery attacks, allowing an attacker to perform unwanted actions on behalf of a logged-in user.
Is there a workaround for CVE-2024-43338 if immediate patching is not possible?
A potential workaround for CVE-2024-43338 includes reviewing user permissions and restricting access until the software can be updated.