Homey WordPress Theme Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Homey theme for WordPress, affecting versions through 2.4.3. The issue arises from inadequate nonce validation in the 'homey_verify_user_manually' function, allowing unauthenticated attackers to manipulate user verification by sending forged requests. Exploitation requires tricking a site administrator into clicking a link or performing a similar action.

Impact

Exploitation of this vulnerability could lead to unauthorized user verification, potentially allowing attackers to gain elevated privileges or access on the affected WordPress site.

Remediation

Users are advised to update the Homey WordPress theme to version 2.4.4 or a later patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.