CVE-2024-10814
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-10814 is a serious vulnerability affecting the Code Embed plugin for WordPress. This issue allows authenticated attackers with contributor-level access or higher to execute Server-Side Request Forgeries (SSRF) through the ce_get_file() function. SSRF attacks enable attackers to make web requests originating from the vulnerable application, potentially allowing them to query and modify sensitive information from internal services. All versions of the plugin up to and including 2.5 are vulnerable to this issue. Users are strongly encouraged to update to the latest version or disable the plugin to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.