Cross-Site Request Forgery Vulnerability in WP Royal Ashe Theme by WP Royal
CVE-2024-37478

4.3MEDIUM

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
2 January 2025

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Royal Ashe Theme, impacting versions from an unknown release up to 2.233. This vulnerability enables attackers to trick users into executing unwanted actions on a web application in which they are currently authenticated, potentially compromising user accounts and sensitive data. It is crucial for users and administrators of the Ashe Theme to apply the necessary updates and security patches to mitigate this risk.

Affected Version(s)

Ashe <= 2.233

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dhabaleshwar Das (Patchstack Alliance)
.