CVE-2024-5076: WP eMember < 10.6.6 - Bulk Delete via CSRF
Published Jul 13, 2024
·Updated
The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
Affected Software
2 affected components
wp-eMember WordPress plugin<10.6.6
Tipsandtricks-hq Wp Emember Wordpress<10.6.6
Event History
Jul 13, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5076?
The severity of CVE-2024-5076 is classified as moderate due to the potential for CSRF attacks affecting user actions.
2
How do I fix CVE-2024-5076?
To fix CVE-2024-5076, update the wp-eMember WordPress plugin to version 10.6.6 or later.
3
What types of attacks are possible with CVE-2024-5076?
CVE-2024-5076 allows attackers to exploit CSRF vulnerabilities, potentially making logged-in users perform unwanted actions.
4
Which versions of the wp-eMember plugin are affected by CVE-2024-5076?
CVE-2024-5076 affects versions of the wp-eMember WordPress plugin prior to version 10.6.6.
5
Is my website at risk if I use an older version of wp-eMember?
Yes, if you are using an older version of wp-eMember before 10.6.6, your website is at risk of CSRF attacks as described in CVE-2024-5076.