CVE-2024-37450: WordPress Benevolent theme <= 1.3.4 - Cross Site Request Forgery (CSRF) vulnerability
Published Jan 2, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in raratheme Benevolent benevolent allows Cross Site Request Forgery.This issue affects Benevolent: from n/a through <= 1.3.4.
Affected Software
3 affected components
Rara Theme Benevolent<=1.3.4
WordPress Benevolent theme<=1.3.4
Rarathemes Benevolent Wordpress<1.3.5
Remediation
Information
Update the WordPress Benevolent theme to the latest available version (at least 1.3.5).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37450?
CVE-2024-37450 is classified as a moderate severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-37450?
To fix CVE-2024-37450, upgrade Rara Theme Benevolent to version 1.3.5 or higher immediately.
3
What is the impact of CVE-2024-37450?
The impact of CVE-2024-37450 allows attackers to perform unauthorized actions on behalf of authenticated users.
4
Which versions of Rara Theme are affected by CVE-2024-37450?
CVE-2024-37450 affects Rara Theme Benevolent from versions n/a through 1.3.4.
5
Is there a workaround for CVE-2024-37450?
Currently, there are no officially recommended workarounds for CVE-2024-37450; upgrading is the best solution.