CVE · Medium

CVE-2024-7422 — Theme My Login [theme-my-login] < 7.1.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7422 Theme My Login [theme-my-login] < 7.1.8 Cross-Site Request Forgery (CSRF) Medium 4.3 < 7.1.8 7.1.8 2024-08-15

CVE-2024-7422

The Theme My Login plugin for WordPress contains a security flaw in versions up to 7.1.7, which allows attackers to manipulate theme settings without proper authorization. This vulnerability is caused by inadequate validation of certain administrative requests, specifically those made to the tml_admin_save_ms_settings function. In multi-site environments, an unauthenticated attacker can exploit this weakness by tricking a site administrator into performing a specific action.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.