CVE-2024-49685: WordPress Custom Twitter Feeds plugin <= 2.2.3 - Cross Site Request Forgery (CSRF) vulnerability
Published Oct 31, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds allows Cross Site Request Forgery.This issue affects Custom Twitter Feeds (Tweets Widget): from n/a through <= 2.2.3.
Affected Software
3 affected components
Smashballoon Custom Twitter Feeds Wordpress<2.2.4
Smash Balloon Custom Twitter Feeds<=2.2.3
WordPress Custom Twitter Feeds<=2.2.3
Remediation
Information
Update to 2.2.4 or a higher version.
Event History
Oct 31, 2024
CVE Published
via MITRE·09:59 AM
Data Sourced
via MITRE·09:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-49685?
CVE-2024-49685 is classified as a high severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-49685?
To fix CVE-2024-49685, upgrade Smash Balloon Custom Twitter Feeds to version 2.2.4 or later.
3
What versions are affected by CVE-2024-49685?
CVE-2024-49685 affects all versions of Smash Balloon Custom Twitter Feeds from n/a up to 2.2.3.
4
What type of vulnerability is CVE-2024-49685?
CVE-2024-49685 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Who is impacted by CVE-2024-49685?
Users of Smash Balloon Custom Twitter Feeds plugin versions 2.2.3 and below are impacted by CVE-2024-49685.