CVE-2024-8245: GamiPress - Reset User <= 1.0.0 - GamiPress User Data Removal via CSRF
Published May 15, 2025
·Updated
The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Affected Software
2 affected components
GamiPress GamiPress<1.0.1
GamiPress Gamipress - Reset User Wordpress<1.0.1
Event History
May 15, 2025
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-8245?
CVE-2024-8245 has a medium severity rating due to the potential for authenticated attackers to exploit it via CSRF.
2
How do I fix CVE-2024-8245?
To fix CVE-2024-8245, update the GamiPress WordPress plugin to version 1.0.1 or later.
3
What are the potential impacts of CVE-2024-8245?
CVE-2024-8245 could allow unauthorized changes to plugin settings by attackers through CSRF attacks.
4
Is CVE-2024-8245 present in older versions of GamiPress?
Yes, CVE-2024-8245 affects all versions of GamiPress prior to 1.0.1.
5
Who is affected by CVE-2024-8245?
Administrators of WordPress sites using GamiPress versions before 1.0.1 are at risk due to CVE-2024-8245.