Cross-Site Request Forgery Vulnerability in WP Travel Engine by WP Travel
CVE-2024-37272
4.3MEDIUM
What is CVE-2024-37272?
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Travel Monster theme for the WP Travel Engine. This vulnerability allows attackers to send unauthorized commands from a user’s browser without their consent. Affected versions include all prior to 1.1.2, which may expose users to significant security risks. Website administrators are encouraged to take immediate action to secure their installations by applying the necessary patches and updates to mitigate potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Travel Monster <= 1.1.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dhabaleshwar Das (Patchstack Alliance)