CVE-2024-37104: WordPress Chic Lite theme <= 1.1.3 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in raratheme Chic Lite chic-lite allows Cross Site Request Forgery.This issue affects Chic Lite: from n/a through <= 1.1.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37104?
CVE-2024-37104 is a cross-site request forgery (CSRF) vulnerability that could allow an attacker to perform unauthorized actions on behalf of a user.
How do I fix CVE-2024-37104?
To fix CVE-2024-37104, update the Rara Chic Lite theme to version 1.1.4 or later where the vulnerability is addressed.
Who is affected by CVE-2024-37104?
CVE-2024-37104 affects users of Rara Chic Lite and WordPress Chic Lite themes versions up to and including 1.1.3.
What types of attacks can CVE-2024-37104 enable?
CVE-2024-37104 can enable unauthorized actions on a website if a user is tricked into executing malicious requests.
Is authentication required to exploit CVE-2024-37104?
CVE-2024-37104 does not require authentication, making it particularly dangerous as it can target logged-in users.