CVE-2024-43984: WordPress Podlove Podcast Publisher plugin <= 4.1.13 - CSRF to Remote Code Execution (RCE) vulnerability
Published Oct 31, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.
Affected Software
3 affected components
podlove Podlove Podcast Publisher WordPress<4.1.14
podlove Podlove Podcast Publisher<=4.1.13
WordPress Podlove Podcast Publisher<=4.1.13
Remediation
Information
Update to 4.1.14 or a higher version.
Event History
Oct 31, 2024
CVE Published
via MITRE·10:02 AM
Data Sourced
via MITRE·10:02 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43984?
CVE-2024-43984 is identified as a Cross-Site Request Forgery (CSRF) vulnerability that can allow code injection.
2
How do I fix CVE-2024-43984?
To fix CVE-2024-43984, update Podlove Podcast Publisher to the latest version beyond 4.1.13.
3
What versions of Podlove Podcast Publisher are affected by CVE-2024-43984?
CVE-2024-43984 affects Podlove Podcast Publisher from versions n/a through 4.1.13.
4
Can CVE-2024-43984 lead to remote code execution?
Yes, CVE-2024-43984 can potentially lead to remote code execution due to the code injection risk.
5
Is CVE-2024-43984 a common vulnerability in WordPress plugins?
Yes, CVE-2024-43984 is a common type of CSRF vulnerability found in WordPress plugins like Podlove Podcast Publisher.