Conversation
supportThere is a cross-scripting vulnerability with the dashboard widget. It was reported back in May. CVE-2024-35689 It has apparently not been patched yet. The page I need help with: [ log in to see the link]
Hi @mom2nine , The vulnerability you reported is already fixed in version 5.2.4, which was updated on 08 Jun 2024 . Please check the reference in CVE-2024-35689: https://patchstack.com/database/vulnerability/wp-analytify/wordpress-analytify-plugin-5-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve . Kindly, update the Analytify plugin to the latest version 5.3.1 if you are still using the old one. Thank you!
Hi @mom2nine , The vulnerability you reported is already fixed in version 5.2.4, which was updated on 08 Jun 2024 . Please check the reference in CVE-2024-35689: https://patchstack.com/database/vulnerability/wp-analytify/wordpress-analytify-plugin-5-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve . Kindly, update the Analytify plugin to the latest version 5.3.1 if you are still using the old one. Thank you!