CVE-2024-2262: WooCommerce Product Filter < 1.4.4 - Filter Deletion via CSRF
Published Apr 1, 2024
·Updated
Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs
Affected Software
3 affected components
Themify WordPress plugin<1.4.4
WooCommerce Product Filter<1.4.4
Themify Woocommerce Product Filter Wordpress<1.4.4
Event History
Apr 1, 2024
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-2262?
CVE-2024-2262 has a moderate severity level due to its potential for CSRF attacks that could allow unauthorized actions.
2
How do I fix CVE-2024-2262?
To fix CVE-2024-2262, upgrade the Themify WordPress plugin to version 1.4.4 or newer.
3
What systems are affected by CVE-2024-2262?
CVE-2024-2262 affects versions of the Themify WordPress plugin prior to 1.4.4.
4
Can CVE-2024-2262 lead to data loss?
Yes, CVE-2024-2262 could lead to data loss as it may allow attackers to delete arbitrary filters.
5
Who is at risk from CVE-2024-2262?
Users of the Themify WordPress plugin who have not updated to version 1.4.4 are at risk from CVE-2024-2262.