Junglewise Threat Intelligence

CVE-2024-37496: Rara Themes Metro Magazine Missing Authorization in notice dismissal

CVE-2024-37496 · Severity: medium · CVSS 4.3 · Published 2026-06-17

Executive brief

Metro Magazine, a WordPress theme used for news and magazine-style websites, contains a security flaw in how it handles administrative notifications. An attacker could trick a site administrator into clicking a malicious link, which would allow the attacker to dismiss important system notices or alerts without authorization. While this does not directly expose sensitive data, it can be used to hide security warnings or disrupt the administrative workflow of the website.

Technical details

A Broken Access Control vulnerability (CWE-862) exists in the Metro Magazine theme for WordPress through version 1.3.7. The flaw is located in the administrative notice dismissal logic, which fails to properly validate the authorization or origin (nonce) of the request. An unauthenticated attacker can exploit this by using social engineering to induce a privileged user (such as an administrator) to perform an action, like clicking a crafted link. Successful exploitation allows the attacker to dismiss notices on the WordPress dashboard, potentially hiding critical system information. The issue is resolved in version 1.3.8.

Affected products

  • Rara Themes Metro Magazine <= 1.3.7

Timeline

  • 2024-01-30: other: Reported by researcher Dhabaleshwar Das
  • 2024-07-04: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date

References

Related threats