CVE-2024-37467

WordPress Hestia theme <= 3.1.2 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in themeisle Hestia hestia allows Cross Site Request Forgery.This issue affects Hestia: from n/a through <= 3.1.2.


We have discovered 10,228 live websites that are affected by CVE-2024-37467.

Run a Free Instant Scan




Affected Software

Product  Hestia
Category Wordpress Themes
Vulnerable Domains10,228 live websites (39% of Hestia install base)
Vulnerable Versions
  • from 0 through 3.1.2
Vulnerable Versions Count114 versions ( 82% of all versions)



Details

  • Published - Jan 2, 2025
  • Updated - Apr 28, 2026

Credits

  • Dhabaleshwar Das | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2024-37467
United States1,861 websites



Germany1,285 websites
France1,230 websites
Poland505 websites
Italy483 websites
Netherlands421 websites
GB398 websites
Japan341 websites
Russia284 websites
Spain255 websites

Website Distribution by TLD

Number of websites using CVE-2024-37467
.com3,175 websites
.de863 websites
.fr579 websites
.org490 websites
.pl400 websites
.nl400 websites
.it349 websites
.net257 websites
.co.uk229 websites
.ru222 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-37467

Top websites that are affected by CVE-2024-37467. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.com United States**,***
*********.com France***,***
*********.de Germany***,***
************.us United States***,***
********.com Italy***,***
**********.news United States***,***
***********.com Argentina***,***
*********.cz Czech Republic***,***
********************.com United States***,***
**************.net United States***,***
See full domain list

FAQ

A total of 10,228 websites have been identified as vulnerable to CVE-2024-37467, based on global website indexing conducted by WebTechSurvey.
The Hestia is affected by the CVE-2024-37467 vulnerability.
Hestia versions up to and including 3.1.2 are vulnerable to CVE-2024-37467.