CVE-2024-3610: WP Child Theme Generator <= 1.1.1 - Missing Authorization to Unauthenticated Child Theme Creation/Activation
The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wctgeasychildtheme() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to create a blank child theme and activate it cause the site to whitescreen.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3610?
CVE-2024-3610 has been classified as a high severity vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2024-3610?
To fix CVE-2024-3610, you should update the WP Child Theme Generator plugin to version 1.1.2 or later.
Who is affected by CVE-2024-3610?
CVE-2024-3610 affects all versions of the WP Child Theme Generator plugin up to and including 1.1.1.
What type of attack can exploit CVE-2024-3610?
CVE-2024-3610 can be exploited by unauthenticated attackers to create or modify child themes due to missing capability checks.
Is there a known exploit for CVE-2024-3610?
As of now, there are no public reports of a known exploit specifically targeting CVE-2024-3610.