Cross-Site Request Forgery in BuddyBoss Theme by BuddyBoss LLC
CVE-2024-37925
5.4MEDIUM
What is CVE-2024-37925?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the BuddyBoss Theme provided by BuddyBoss LLC. This security flaw allows malicious actors to perform unauthorized actions on behalf of users without their consent. The vulnerability impacts all versions from release up to and including version 2.4.61, which raises significant concerns for sites utilizing this theme. Proper validation of user actions is essential to mitigate potential exploitation of this issue.
Affected Version(s)
BuddyBoss Theme <= 2.4.61