CVE-2024-6075: WP eStore < 8.5.5 - Coupon Deletion via CSRF
Published Jul 15, 2024
·Updated
The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
Affected Software
1 affected component
Tipsandtricks-hq Wp Estore Wordpress<8.5.5
Event History
Jul 15, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-6075?
CVE-2024-6075 is classified as a medium severity vulnerability due to the lack of CSRF checks.
2
How do I fix CVE-2024-6075?
To fix CVE-2024-6075, update the wp-cart-for-digital-products WordPress plugin to version 8.5.5 or later.
3
What type of vulnerability is CVE-2024-6075?
CVE-2024-6075 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the wp-cart-for-digital-products plugin.
4
Who is affected by CVE-2024-6075?
Users of the wp-cart-for-digital-products WordPress plugin versions prior to 8.5.5 are affected by CVE-2024-6075.
5
What actions can attackers perform using CVE-2024-6075?
Attackers can exploit CVE-2024-6075 to make logged-in users execute unwanted actions on the site.