PT-2024-27948 · WordPress · Sola Testimonials

Yuta Takanashi

·

Published

2024-07-04

·

Updated

2024-07-09

·

CVE-2024-38345

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Sola Testimonials versions prior to 3.0.0
Description A cross-site request forgery issue exists, allowing an attacker to trick a user into accessing a malicious page when logged in to a WordPress site with the affected plugin enabled. This could result in the user performing unintended operations on the site.
Recommendations For versions prior to 3.0.0, update to version 3.0.0 or later to resolve the issue.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-38345

Affected Products

Sola Testimonials