CVE-2024-49273: WordPress ProfileGrid plugin <= 5.9.3 - Cross Site Request Forgery (CSRF) vulnerability
Published Oct 21, 2024
·Updated
Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities.This issue affects ProfileGrid : from n/a through <= 5.9.3.
Affected Software
1 affected component
Metagauss Profilegrid Wordpress<=5.9.3
Remediation
Information
Update to 5.9.3.1 or a higher version.
Event History
Oct 21, 2024
CVE Published
via MITRE·11:13 AM
Data Sourced
via MITRE·11:13 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-49273?
CVE-2024-49273 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2024-49273?
To fix CVE-2024-49273, update the ProfileGrid plugin to version 5.9.4 or later.
3
What systems are affected by CVE-2024-49273?
CVE-2024-49273 affects ProfileGrid versions from n/a through 5.9.3.
4
What type of vulnerability is CVE-2024-49273?
CVE-2024-49273 is a missing authorization vulnerability.
5
Who is the vendor associated with CVE-2024-49273?
The vendor associated with CVE-2024-49273 is Metagauss.