CVE-2024-54355: WordPress WP Mailster plugin <= 1.8.17.0 - Cross Site Request Forgery (CSRF) vulnerability
Published Dec 16, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in brandtoss WP Mailster wp-mailster allows Cross Site Request Forgery.This issue affects WP Mailster: from n/a through <= 1.8.17.0.
Affected Software
3 affected components
Wpmailster Wp Mailster Wordpress<1.8.17
brandtoss WP Mailster<=1.8.17.0
WordPress WP Mailster<=1.8.17.0
Remediation
Information
Update the WordPress WP Mailster wordpress plugin to the latest available version (at least 1.8.18.0).
Event History
Dec 16, 2024
CVE Published
via MITRE·02:14 PM
Data Sourced
via MITRE·02:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54355?
CVE-2024-54355 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-54355?
To fix CVE-2024-54355, upgrade WP Mailster to a version higher than 1.8.17.0.
3
What versions of WP Mailster are affected by CVE-2024-54355?
CVE-2024-54355 affects all versions of WP Mailster up to and including 1.8.17.0.
4
What type of vulnerability is CVE-2024-54355?
CVE-2024-54355 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Who is the vendor for the product related to CVE-2024-54355?
The vendor for the product related to CVE-2024-54355 is Brandtoss.