Cross-Site Request Forgery (CSRF) vulnerability in multiple themes by KlbTheme
Summary
| CVE | CVE-2023-49838 |
|---|---|
| State | PUBLISHED |
| Assigner | Patchstack |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-03-26 09:15:09 UTC |
| Updated | 2026-04-28 19:22:29 UTC |
| Description | Cross-Site Request Forgery (CSRF) vulnerability in KlbTheme Clotya theme, KlbTheme Cosmetsy theme, KlbTheme Furnob theme, KlbTheme Bacola theme, KlbTheme Partdo theme, KlbTheme Medibazar theme, KlbTheme Machic theme.This issue affects Clotya theme: from n/a through 1.1.6; Cosmetsy theme: from n/a through 1.7.7; Furnob theme: from n/a through 1.2.2; Bacola theme: from n/a through 1.3.3; Partdo theme: from n/a through 1.1.1; Medibazar theme: from n/a through 1.8.6; Machic theme: from n/a through 1.2.8. |
Risk And Classification
Primary CVSS: v3.1 4.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS: 0.002450000 probability, percentile 0.477970000 (date 2026-04-28)
Problem Types: CWE-352 | CWE-352 CWE-352 Cross-Site Request Forgery (CSRF)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
| 3.1 | CNA | CVSS | 4.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | KlbTheme | Clotya Theme | affected n/a 1.1.6 custom | Not specified |
| CNA | KlbTheme | Cosmetsy Theme | affected n/a 1.7.7 custom | Not specified |
| CNA | KlbTheme | Furnob Theme | affected n/a 1.2.2 custom | Not specified |
| CNA | KlbTheme | Bacola Theme | affected n/a 1.3.3 custom | Not specified |
| CNA | KlbTheme | Partdo Theme | affected n/a 1.1.1 custom | Not specified |
| CNA | KlbTheme | Medibazar Theme | affected n/a 1.8.6 custom | Not specified |
| CNA | KlbTheme | Machic Theme | affected n/a 1.2.8 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| patchstack.com/database/vulnerability/furnob/wordpress-furnob-theme-1-2-2-cr... | af854a3a-2127-422b-91ae-364da2661108 | patchstack.com | |
| patchstack.com/database/vulnerability/partdo/wordpress-partdo-theme-1-1-1-cr... | af854a3a-2127-422b-91ae-364da2661108 | patchstack.com | |
| patchstack.com/database/vulnerability/clotya/wordpress-clotya-theme-1-1-6-cr... | af854a3a-2127-422b-91ae-364da2661108 | patchstack.com | |
| patchstack.com/database/vulnerability/machic/wordpress-machic-theme-1-2-8-cr... | af854a3a-2127-422b-91ae-364da2661108 | patchstack.com | |
| patchstack.com/database/vulnerability/cosmetsy/wordpress-cosmetsy-theme-1-7-... | af854a3a-2127-422b-91ae-364da2661108 | patchstack.com | |
| patchstack.com/database/vulnerability/medibazar/wordpress-medibazar-theme-1-... | af854a3a-2127-422b-91ae-364da2661108 | patchstack.com | |
| patchstack.com/database/vulnerability/bacola/wordpress-bacola-theme-1-3-3-cr... | af854a3a-2127-422b-91ae-364da2661108 | patchstack.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: FearZzZz (Patchstack Alliance) (en)
There are currently no legacy QID mappings associated with this CVE.