CVE-2024-37503: WordPress Lawyer Landing Page theme <= 1.2.4 - Cross Site Request Forgery (CSRF) vulnerability
Published Jan 2, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Cross Site Request Forgery.This issue affects Lawyer Landing Page: from n/a through <= 1.2.4.
Affected Software
3 affected components
Rara Lawyer Landing Page<=1.2.4
WordPress Lawyer Landing Page<=1.2.4
Rarathemes Lawyer Landing Page Wordpress<1.2.5
Remediation
Information
Update the WordPress Lawyer Landing Page theme to the latest available version (at least 1.2.5).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37503?
CVE-2024-37503 has been rated as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-37503?
To fix CVE-2024-37503, update the Rara Lawyer Landing Page theme to version 1.2.5 or later.
3
What versions of the Lawyer Landing Page are affected by CVE-2024-37503?
CVE-2024-37503 affects versions of the Lawyer Landing Page theme up to and including version 1.2.4.
4
What type of vulnerability is CVE-2024-37503?
CVE-2024-37503 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2024-37503 be exploited remotely?
Yes, CVE-2024-37503 can be exploited remotely by an attacker to perform unauthorized actions on behalf of users.