CVE-2024-37491
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 2, 2025
CWE ID 352
Summary
CVE-2024-37491 is a Cross-Site Request Forgery (CSRF) vulnerability affecting the Apollo13Themes Rife Free plugin. This issue permits malicious actors to execute unintended actions on a user's behalf, potentially leading to unauthorized changes. The vulnerability impacts Rife Free versions from n/a through 2.4.18, so it is crucial for users to update their installations as soon as a patch becomes available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.