CVE-2024-1943

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 28, 2024
Updated: Jan 8, 2025
CWE ID 352

Summary

CVE-2024-1943 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Yuki theme for WordPress. Versions up to and including 1.3.14 are impacted by this issue. The root cause is the lack of proper nonce validation in the reset_customizer_options() function, which leaves the theme settings susceptible to manipulation. Unauthenticated attackers can exploit this vulnerability by tricking site administrators into performing an action, like clicking on a malicious link, to execute a forged request and reset the themes settings.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share