CVE-2024-37925: WordPress BuddyBoss Theme theme <= 2.4.61 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme allows Cross Site Request Forgery.This issue affects BuddyBoss Theme: from n/a through 2.4.61.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme buddyboss-theme allows Cross Site Request Forgery.This issue affects BuddyBoss Theme: from n/a through <= 2.4.61.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37925?
CVE-2024-37925 has a high severity rating due to its potential to allow Cross-Site Request Forgery attacks.
How do I fix CVE-2024-37925?
To fix CVE-2024-37925, update the BuddyBoss Theme to version 2.4.62 or later.
Which versions of the BuddyBoss Theme are affected by CVE-2024-37925?
CVE-2024-37925 affects all versions of the BuddyBoss Theme from n/a through 2.4.61.
What type of vulnerability is CVE-2024-37925?
CVE-2024-37925 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
Who is the vendor affected by CVE-2024-37925?
The vendor affected by CVE-2024-37925 is BUDDYBOSS LLC.