Cross-Site Request Forgery Vulnerability in Mesmerize by Horea Radu
CVE-2024-37431

4.3MEDIUM

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
2 January 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Mesmerize theme developed by Horea Radu. This security flaw allows attackers to exploit the application by forging requests on behalf of authenticated users. As a result, malicious users could potentially perform unauthorized actions, leading to significant security risks for affected sites. This issue affects all versions of Mesmerize from n/a to 1.6.120, raising concerns about the integrity and safety of user interactions within the application. Site administrators are urged to apply necessary updates and security patches immediately to mitigate these risks.

Affected Version(s)

Mesmerize <= 1.6.120

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dhabaleshwar Das (Patchstack Alliance)
.