CVE-2024-37458: WordPress Highlight theme <= 1.0.29 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in extendthemes Highlight highlight allows Cross Site Request Forgery.This issue affects Highlight: from n/a through <= 1.0.29.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37458?
CVE-2024-37458 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to unauthorized actions on behalf of authenticated users.
How do I fix CVE-2024-37458?
To remediate CVE-2024-37458, update the ExtendThemes Highlight to a version beyond 1.0.29 or apply any available security patches.
What software is affected by CVE-2024-37458?
CVE-2024-37458 impacts ExtendThemes Highlight versions up to and including 1.0.29.
Can CVE-2024-37458 be exploited remotely?
Yes, CVE-2024-37458 can be exploited remotely, allowing attackers to perform actions without user consent.
What are the potential impacts of CVE-2024-37458?
The potential impacts of CVE-2024-37458 include unauthorized changes to user data and the possibility of account takeovers.