CVE-2024-2904: WordPress Calliope theme <= 1.0.33 - Cross Site Request Forgery (CSRF) vulnerability
Published Mar 26, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Calliope.This issue affects Calliope: from n/a through 1.0.33.
Affected Software
3 affected components
Extend Themes Calliope<=1.0.33
WordPress Calliope<=1.0.33
ExtendThemes Calliope Wordpress<1.0.35
Remediation
Information
Update to 1.0.35 or a higher version.
Event History
Mar 26, 2024
CVE Published
via MITRE·09:45 AM
Data Sourced
via MITRE·09:45 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-2904?
CVE-2024-2904 is classified as a Cross-Site Request Forgery (CSRF) vulnerability affecting Extend Themes Calliope version 1.0.33.
2
How do I fix CVE-2024-2904?
To fix CVE-2024-2904, update the Extend Themes Calliope to a version that is newer than 1.0.33.
3
What versions are affected by CVE-2024-2904?
CVE-2024-2904 affects Extend Themes Calliope from an unspecified version up to and including 1.0.33.
4
What type of vulnerability is CVE-2024-2904?
CVE-2024-2904 is a Cross-Site Request Forgery (CSRF) vulnerability that can allow unauthorized actions on behalf of a user.
5
Who is the vendor for CVE-2024-2904?
The vendor for CVE-2024-2904 is Extend Themes.