CVE-2024-37937: WordPress Rara Business theme <= 1.2.5 - Cross Site Request Forgery (CSRF) vulnerability
Published Jan 2, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in raratheme Rara Business rara-business allows Cross Site Request Forgery.This issue affects Rara Business: from n/a through <= 1.2.5.
Affected Software
3 affected components
Rara Business<=1.2.5
WordPress Rara Business theme<=1.2.5
Rarathemes Rara Business Wordpress<1.2.6
Remediation
Information
Update the WordPress Rara Business theme to the latest available version (at least 1.2.6).
Event History
Jan 2, 2025
CVE Published
via MITRE·12:01 PM
Data Sourced
via MITRE·12:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-37937?
CVE-2024-37937 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-37937?
To fix CVE-2024-37937, update the Rara Business theme to a version that is higher than 1.2.5.
3
Which software is affected by CVE-2024-37937?
CVE-2024-37937 affects Rara Business theme versions up to and including 1.2.5.
4
What types of attacks are possible with CVE-2024-37937?
CVE-2024-37937 allows attackers to perform unauthorized actions on behalf of an authenticated user through CSRF.
5
Is there any workaround for CVE-2024-37937?
No specific workaround is recommended for CVE-2024-37937; updating to a patched version is advised.