CVE-2024-2262

CVE-2024-2262: WooCommerce Product Filter < 1.4.4 - Filter Deletion via CSRF

Vendor Unknown
Product Themify
Published April 1, 2024
Last update August 21, 2024

CVSS base score

What the vulnerability does

01Description

Themify WordPress plugin before 1.4.4 does not have CSRF check in its bulk action, which could allow attackers to make logged in users delete arbitrary filters via CSRF attack, granted they know the related filter slugs

Key dates

02Disclosure timeline

April 1, 2024 CVE published
August 21, 2024 Record updated