CVE-2024-31386

Multiple WordPress themes affected by Cross-Site Request Forgery vulnerability

Description

Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes HappenStance, Marsian i-excel, Out the Box Panoramic, Modernthemesnet Sensible WP.This issue affects X-T9: from n/a through 1.19.0; Lightning: from n/a through 15.18.0; Default Mag: from n/a through 1.3.5; Namaha: from n/a through 1.0.40; CityLogic: from n/a through 1.1.29; i-max: from n/a through 1.6.2; Emmet Lite: from n/a through 1.7.5; Decode: from n/a through 3.15.3; Sliding Door: from n/a through 3.3; Shopstar!: from n/a through 1.1.33; Gridsby: from n/a through 1.3.0; HappenStance: from n/a through 3.0.1; i-excel: from n/a through 1.7.9; Panoramic: from n/a through 1.1.56; Sensible WP: from n/a through 1.3.1.

Remediation

Solution:

  • Update X-T9 to 1.19.1 or a higher version. Update Lightning to 15.19.0 or a higher version. Update Default Mag to 1.3.6 or a higher version. Update Namaha to 1.0.41 or a higher version. Update CityLogic to 1.1.30 or a higher version. Update Emmet Lite to 1.7.8 or a higher version. Update Sliding Door to 3.4 or a higher version. Update Shopstar! to 1.1.34 or a higher version. Update Panoramic to 1.1.57 or a higher version.

Category

4.3
CVSS
Severity: Medium
CVSS 3.1 •
EPSS 0.34%
Affected: Hidekazu Ishikawa X-T9
Affected: Hidekazu Ishikawa Lightning
Affected: themeinwp Default Mag
Affected: Out the Box Namaha
Affected: Out the Box CityLogic
Affected: Marsian i-max
Affected: Jetmonsters Emmet Lite
Affected: Macho Themes Decode
Affected: Wayneconnor Sliding Door
Affected: Out the Box Shopstar!
Affected: Modernthemesnet Gridsby
Affected: TT Themes HappenStance
Affected: Marsian i-excel
Affected: Out the Box Panoramic
Affected: Modernthemesnet Sensible WP
Published at:
Updated at:

References

Link Tags
https://patchstack.com/database/vulnerability/x-t9/wordpress-x-t9-theme-1-19-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/lightning/wordpress-lightning-theme-15-18-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/default-mag/wordpress-default-mag-theme-1-3-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/namaha/wordpress-namaha-theme-1-0-40-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/citylogic/wordpress-citylogic-theme-1-1-29-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/i-max/wordpress-i-max-theme-1-6-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/emmet-lite/wordpress-emmet-lite-theme-1-7-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/decode/wordpress-decode-theme-3-15-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/sliding-door/wordpress-sliding-door-theme-3-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/shopstar/wordpress-shopstar-theme-1-1-33-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/gridsby/wordpress-gridsby-theme-1-3-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/happenstance/wordpress-happenstance-theme-3-0-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/i-excel/wordpress-i-excel-theme-1-7-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/panoramic/wordpress-panoramic-theme-1-1-56-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry
https://patchstack.com/database/vulnerability/sensible-wp/wordpress-sensible-wp-theme-1-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve vdb entry

Frequently Asked Questions

What is the severity of CVE-2024-31386?
CVE-2024-31386 has been scored as a medium severity vulnerability.
How to fix CVE-2024-31386?
To fix CVE-2024-31386: Update X-T9 to 1.19.1 or a higher version. Update Lightning to 15.19.0 or a higher version. Update Default Mag to 1.3.6 or a higher version. Update Namaha to 1.0.41 or a higher version. Update CityLogic to 1.1.30 or a higher version. Update Emmet Lite to 1.7.8 or a higher version. Update Sliding Door to 3.4 or a higher version. Update Shopstar! to 1.1.34 or a higher version. Update Panoramic to 1.1.57 or a higher version.
Is CVE-2024-31386 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2024-31386 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2024-31386?
CVE-2024-31386 affects Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes HappenStance, Marsian i-excel, Out the Box Panoramic, Modernthemesnet Sensible WP.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.