Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs
History

Tue, 13 May 2025 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Themify
Themify woocommerce Product Filter
Weaknesses CWE-352
CPEs cpe:2.3:a:themify:woocommerce_product_filter:*:*:*:*:*:wordpress:*:*
Vendors & Products Themify
Themify woocommerce Product Filter

Thu, 22 Aug 2024 00:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-04-01T05:00:01.688Z

Updated: 2024-08-21T22:39:32.516Z

Reserved: 2024-03-07T14:14:07.699Z

Link: CVE-2024-2262

cve-icon Vulnrichment

Updated: 2024-08-01T19:03:39.362Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-01T05:15:07.937

Modified: 2025-05-13T01:01:40.560

Link: CVE-2024-2262

cve-icon Redhat

No data.