CVE-2024-33688: WordPress Teluro theme <= 1.0.31 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 26, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Teluro.This issue affects Teluro: from n/a through 1.0.31.
Affected Software
3 affected components
Extend Themes Teluro<=1.0.31
WordPress Teluro<=1.0.31
ExtendThemes Teluro Wordpress<1.0.36
Remediation
Information
Update to 1.0.36 or a higher version.
Event History
Apr 26, 2024
CVE Published
via MITRE·12:55 PM
Data Sourced
via MITRE·12:55 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33688?
CVE-2024-33688 is considered a medium severity Cross-Site Request Forgery vulnerability.
2
What versions are affected by CVE-2024-33688?
CVE-2024-33688 affects Extend Themes Teluro versions up to and including 1.0.31.
3
How do I fix CVE-2024-33688?
To fix CVE-2024-33688, update Extend Themes Teluro to the latest version that addresses this vulnerability.
4
What is a Cross-Site Request Forgery vulnerability like CVE-2024-33688?
A Cross-Site Request Forgery vulnerability allows an attacker to execute unauthorized commands on behalf of a user.
5
Is CVE-2024-33688 specific to WordPress?
Yes, CVE-2024-33688 affects the WordPress Teluro theme as well as its Extend Themes counterpart.