CVE-2024-31386: Hidekazu Ishikawa Lightning
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes HappenStance, Marsian i-excel, Out the Box Panoramic, Modernthemesnet Sensible WP.This issue affects X-T9: from n/a through 1.19.0; Lightning: from n/a through 15.18.0; Default Mag: from n/a through 1.3.5; Namaha: from n/a through 1.0.40; CityLogic: from n/a through 1.1.29; i-max: from n/a through 1.6.2; Emmet Lite: from n/a through 1.7.5; Decode: from n/a through 3.15.3; Sliding Door: from n/a through 3.3; Shopstar!: from n/a through 1.1.33; Gridsby: from n/a through 1.3.0; HappenStance: from n/a through 3.0.1; i-excel: from n/a through 1.7.9; Panoramic: from n/a through 1.1.56; Sensible WP: from n/a through 1.3.1.
Affected products
- Hidekazu Ishikawa Lightning: up to and including 15.18.0
- Hidekazu Ishikawa X-t9: up to and including 1.19.0
- Jetmonsters Emmet Lite: up to and including 1.7.5
- Macho Themes Decode: up to and including 3.15.3
- Marsian I-Excel: up to and including 1.7.9
- Marsian I-Max: up to and including 1.6.2
- Modernthemesnet Gridsby: up to and including 1.3.0
- Modernthemesnet Sensible Wp: up to and including 1.3.1
- Out The Box Citylogic: up to and including 1.1.29
- Out The Box Namaha: up to and including 1.0.40
- Out The Box Panoramic: up to and including 1.1.56
- Out The Box Shopstar!: up to and including 1.1.33
- Themeinwp Default Mag: up to and including 1.3.5
- Tt Themes Happenstance: up to and including 3.0.1
- Wayneconnor Sliding Door: up to and including 3.3
Published 2024-04-10. Last modified 2026-06-17.