CVE-2024-6136: WP eStore < 8.5.6 - Settings Reset via CSRF
The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6136?
The severity of CVE-2024-6136 is considered to be high due to the potential for CSRF attacks that could compromise user actions.
How do I fix CVE-2024-6136?
To fix CVE-2024-6136, you should update the wp-cart-for-digital-products plugin to version 8.5.6 or later.
What are the potential impacts of CVE-2024-6136?
The potential impacts of CVE-2024-6136 include unauthorized actions being performed by logged-in users due to the lack of CSRF checks.
Which versions of the wp-cart-for-digital-products plugin are affected by CVE-2024-6136?
CVE-2024-6136 affects all versions of the wp-cart-for-digital-products plugin prior to 8.5.6.
Is CVE-2024-6136 associated with any specific WordPress configurations?
CVE-2024-6136 is associated with the wp-cart-for-digital-products plugin used in WordPress installations.