← WordPress Vulnerabilities
WordPress security by component

Browser Theme Color

Browser Theme Color is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jan 31, 2024; the highest published CVSS base score is 4.3.

Plugin slug: browser-theme-color

CVE-2024-22291: Browser Theme Color: Cross-site request forgery

Browser Theme Color is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedJan 31, 2024
Safe version guidanceSee mitigation notes
Published vulnerabilities for browser-theme-color
Safe version
Jan 31, 2024 CVE-2024-22291
Browser Theme Color: Cross-site request forgery
Browser Theme Color is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVD8.8