CVE-2024-49294: WordPress WpBusTicketly plugin <= 5.4.3 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation allows Cross Site Request Forgery.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through <= 5.4.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49294?
CVE-2024-49294 is classified as a critical Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2024-49294?
To fix CVE-2024-49294, upgrade the MagePeople Bus Ticket Booking with Seat Reservation or WordPress WpBusTicketly to the latest version beyond 5.4.3.
What software is affected by CVE-2024-49294?
CVE-2024-49294 affects MagePeople Bus Ticket Booking with Seat Reservation and WordPress WpBusTicketly up to version 5.4.3.
What does CVE-2024-49294 enable an attacker to do?
CVE-2024-49294 allows attackers to exploit Cross-Site Request Forgery to perform actions on behalf of authenticated users.
Who is impacted by CVE-2024-49294?
Any users of MagePeople Bus Ticket Booking with Seat Reservation and WordPress WpBusTicketly versions up to 5.4.3 are at risk from CVE-2024-49294.