CVE-2024-37431: WordPress Mesmerize theme <= 1.6.120 - Cross Site Request Forgery (CSRF) vulnerability
Published Jan 2, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in extendthemes Mesmerize mesmerize allows Cross Site Request Forgery.This issue affects Mesmerize: from n/a through <= 1.6.120.
Affected Software
1 affected component
ExtendThemes Mesmerize<=1.6.120
Remediation
Information
Update the WordPress Mesmerize theme to the latest available version (at least 1.6.124).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37431?
CVE-2024-37431 has a moderate severity level due to its potential for Cross-Site Request Forgery attacks.
2
How do I fix CVE-2024-37431?
To fix CVE-2024-37431, update the Horea Radu Mesmerize to the latest version beyond 1.6.120.
3
Which versions of the Mesmerize theme are affected by CVE-2024-37431?
CVE-2024-37431 affects all versions of the Horea Radu Mesmerize theme up to and including 1.6.120.
4
Can CVE-2024-37431 be exploited remotely?
Yes, CVE-2024-37431 can be exploited remotely through Cross-Site Request Forgery.
5
Is CVE-2024-37431 specific to any platform?
CVE-2024-37431 is specifically related to the Horea Radu Mesmerize theme and its integration with WordPress.