CVE-2024-37451: WordPress Travel Agency theme <= 1.4.9 - Cross Site Request Forgery (CSRF) vulnerability
Published Jan 2, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in raratheme Travel Agency travel-agency allows Cross Site Request Forgery.This issue affects Travel Agency: from n/a through <= 1.4.9.
Affected Software
3 affected components
Rara Theme Travel Agency<=1.4.9
WordPress Travel Agency<=1.4.9
Rarathemes Travel Agency Wordpress<1.5.0
Remediation
Information
Update the WordPress Travel Agency theme to the latest available version (at least 1.5.0).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37451?
CVE-2024-37451 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-37451?
To fix CVE-2024-37451, update the Rara Theme Travel Agency plugin to version 1.5 or later, which contains the necessary security patches.
3
Who is affected by CVE-2024-37451?
CVE-2024-37451 affects users of Rara Theme Travel Agency versions up to and including 1.4.9.
4
What type of attack can CVE-2024-37451 enable?
CVE-2024-37451 can enable attackers to perform Cross-Site Request Forgery attacks, potentially compromising user accounts.
5
Is CVE-2024-37451 being actively exploited in the wild?
As of now, there are no confirmed reports of active exploitation of CVE-2024-37451.