CVE-2024-35770: Davekiss Vimeography

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in Dave Kiss Vimeography: Vimeo Video Gallery WordPress Plugin.This issue affects Vimeography: Vimeo Video Gallery WordPress Plugin: from n/a through 2.4.1.

Affected products

  • Davekiss Vimeography: before 2.4.2 (fixed in 2.4.2)

Published 2024-06-21. Last modified 2026-06-17.