CVE-2024-37508: WordPress Construction Landing Page theme <= 1.3.5 - Cross Site Request Forgery (CSRF) vulnerability
Published Jan 2, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in raratheme Construction Landing Page construction-landing-page allows Cross Site Request Forgery.This issue affects Construction Landing Page: from n/a through <= 1.3.5.
Affected Software
3 affected components
Rara Construction Landing Page<=1.3.5
WordPress Construction Landing Page<=1.3.5
Rarathemes Construction Landing Page Wordpress<1.3.6
Remediation
Information
Update the WordPress Construction Landing Page theme to the latest available version (at least 1.3.6).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37508?
CVE-2024-37508 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-37508?
To fix CVE-2024-37508, update the Rara Construction Landing Page theme to the latest version above 1.3.5.
3
Who is affected by CVE-2024-37508?
CVE-2024-37508 affects users of the Rara Construction Landing Page theme version 1.3.5 or below.
4
What type of vulnerability is CVE-2024-37508?
CVE-2024-37508 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
What can attackers do with CVE-2024-37508?
Attackers can exploit CVE-2024-37508 to perform unauthorized actions on behalf of the authenticated user.