CVE-2024-7422
The Theme My Login plugin for WordPress contains a security flaw in versions up to 7.1.7, which allows attackers to manipulate theme settings without proper authorization. This vulnerability is caused by inadequate validation of certain administrative requests, specifically those made to the tml_admin_save_ms_settings function. In multi-site environments, an unauthenticated attacker can exploit this weakness by tricking a site administrator into performing a specific action.
Based on public CVE data (MITRE/NVD).