HIGH
WordPress AppPresser plugin <= 4.3.0 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 15, 2024
8.8
HIGHCVSS 3.1
EPSS 0.24%
Description
Cross-Site Request Forgery (CSRF) vulnerability in Scott Bolinger AppPresser apppresser allows Cross Site Request Forgery.This issue affects AppPresser: from n/a through <= 4.3.0.
Affected products
-
Affected
- ≥ 0, ≤ 4.3.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Scott Bolinger | AppPresser | unaffected | Affected
|
- < 4.3.1
-
Affected
- ≥ 0, ≤ 4.3.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apppresser | Apppresser | unaffected | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-29270 Advisory
- https://patchstack.com/database/Wordpress/Plugin/apppresser/vulnerability/wordpress-apppresser-mobile-app-framework-plugin-4-3-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb-entry
- https://patchstack.com/database/vulnerability/apppresser/wordpress-apppresser-mobile-app-framework-plugin-4-3-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Apr 15, 2024
Updated Apr 28, 2026
Reserved Apr 1, 2024
Link CVE-2024-31374
CISA Vulnrichment
Updated Apr 15, 2024
Red Hat
No data
GitHub
No data