Missing Authorization Vulnerability in Rara Themes Metro Magazine
CVE-2024-37496

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2026

What is CVE-2024-37496?

The security issue in Rara Themes Metro Magazine stems from a Missing Authorization vulnerability, which allows attackers to exploit incorrectly configured access control settings. This weakness can lead to unauthorized access, potentially compromising sensitive user data. It's crucial for users of Metro Magazine from version n/a through 1.3.7 to assess their security settings and apply necessary updates to mitigate this risk.

Affected Version(s)

Metro Magazine <= 1.3.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dhabaleshwar Das | Patchstack Bug Bounty Program
.