CVE-2024-5808: WP Ajax Contact Form <= 2.2.2 - Arbitrary Email Deletion via CSRF
Published Jul 30, 2024
·Updated
The WP Ajax Contact Form WordPress plugin through 2.2.2 does not have CSRF check in place when deleting emails from the email list, which could allow attackers to make a logged in admin perform such action via a CSRF attack
Affected Software
2 affected components
WordPress WP Ajax Contact Form<=2.2.2
Masdiblogs Wp Ajax Contact Form Wordpress<=2.2.2
Event History
Jul 30, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5808?
CVE-2024-5808 has a medium severity rating due to its potential for CSRF attacks.
2
How do I fix CVE-2024-5808?
To fix CVE-2024-5808, update the WP Ajax Contact Form plugin to version 2.2.3 or later.
3
What vulnerability does CVE-2024-5808 exploit?
CVE-2024-5808 exploits a lack of CSRF checks when deleting emails from the email list in the WP Ajax Contact Form plugin.
4
Who is affected by CVE-2024-5808?
Users of the WP Ajax Contact Form WordPress plugin version 2.2.2 and earlier are affected by CVE-2024-5808.
5
What kind of attack can occur due to CVE-2024-5808?
CVE-2024-5808 can allow attackers to perform unauthorized email deletions via CSRF attacks on logged-in admin users.