CVE · Medium

CVE-2024-32525 — Theme My Login [theme-my-login] < 7.1.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-32525 Theme My Login [theme-my-login] < 7.1.7 Missing Authorization Medium 4.3 < 7.1.7 7.1.7 2024-04-15

CVE-2024-32525

The Theme My Login plugin for WordPress contains a capability check vulnerability in the tml_admin_ajax_dismiss_notice() function affecting versions up to 7.1.6. Authenticated users with subscriber-level privileges or higher can dismiss notices without proper authorization checks. This flaw allows low-privileged attackers to modify plugin data through unauthorized actions. The vulnerability is fixed in version 7.1.7.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.