The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make users vote on any polls, including those they don't have access to via a CSRF attack
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-07-03T06:00:03.922Z

Updated: 2024-08-01T19:03:39.198Z

Reserved: 2024-03-06T19:45:41.389Z

Link: CVE-2024-2235

cve-icon Vulnrichment

Updated: 2024-08-01T19:03:39.198Z

cve-icon NVD

Status : Modified

Published: 2024-07-03T06:15:03.387

Modified: 2024-07-08T14:18:12.410

Link: CVE-2024-2235

cve-icon Redhat

No data.