Cross-Site Request Forgery Vulnerability in Apollo13Themes Rife Free
CVE-2024-37491
4.3MEDIUM
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Rife Free theme developed by Apollo13Themes. This security flaw allows an attacker to trick users into executing unwanted actions on the WordPress site, leading to potential unauthorized functions being performed. The issue impacts all versions of Rife Free from unknown to 2.4.18, highlighting the importance of ensuring that this theme is updated to a secure version. Users are advised to apply necessary patches and adhere to security best practices to mitigate this identified risk.
Affected Version(s)
Rife Free <= 2.4.18
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dhabaleshwar Das (Patchstack Alliance)