CVE-2024-37467: WordPress Hestia theme <= 3.1.2 - Cross Site Request Forgery (CSRF) vulnerability
Published Jan 2, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in themeisle Hestia hestia allows Cross Site Request Forgery.This issue affects Hestia: from n/a through <= 3.1.2.
Affected Software
1 affected component
Themeisle Hestia<=3.1.2
Remediation
Information
Update the WordPress Hestia theme to the latest available version (at least 3.1.3).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37467?
CVE-2024-37467 is classified as a Cross-Site Request Forgery (CSRF) vulnerability in ThemeIsle Hestia, affecting versions up to 3.1.2.
2
How do I fix CVE-2024-37467?
To fix CVE-2024-37467, update ThemeIsle Hestia to the latest version that addresses this CSRF vulnerability.
3
What versions are affected by CVE-2024-37467?
CVE-2024-37467 affects ThemeIsle Hestia versions from n/a through 3.1.2.
4
What type of vulnerability is CVE-2024-37467?
CVE-2024-37467 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Who is the vendor associated with CVE-2024-37467?
The vendor associated with CVE-2024-37467 is ThemeIsle, the creator of the Hestia theme.