Cross-Site Request Forgery Vulnerability in ExtendThemes Highlight Product
CVE-2024-37458

4.3MEDIUM

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
2 January 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ExtendThemes Highlight product, which can allow an attacker to initiate malicious actions on behalf of an authenticated user. This vulnerability affects the Highlight product from version n/a through 1.0.29. If exploited, the attacker could potentially take unauthorized actions without the user's consent. It is crucial for users of the affected versions to implement security measures to mitigate the risk posed by this vulnerability.

Affected Version(s)

Highlight <= 1.0.29

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dhabaleshwar Das (Patchstack Alliance)
.