Cross-Site Request Forgery Vulnerability in WP Travel Engine by WP Travel
CVE-2024-37272
4.3MEDIUM
What is CVE-2024-37272?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Travel Monster theme for the WP Travel Engine. This vulnerability allows attackers to send unauthorized commands from a user’s browser without their consent. Affected versions include all prior to 1.1.2, which may expose users to significant security risks. Website administrators are encouraged to take immediate action to secure their installations by applying the necessary patches and updates to mitigate potential exploits.
Affected Version(s)
Travel Monster 0 <= 1.1.2