CVE-2024-10814

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Nov 9, 2024
Updated: Nov 12, 2024
CWE ID 918

Summary

CVE-2024-10814 is a serious vulnerability affecting the Code Embed plugin for WordPress. This issue allows authenticated attackers with contributor-level access or higher to execute Server-Side Request Forgeries (SSRF) through the ce_get_file() function. SSRF attacks enable attackers to make web requests originating from the vulnerable application, potentially allowing them to query and modify sensitive information from internal services. All versions of the plugin up to and including 2.5 are vulnerable to this issue. Users are strongly encouraged to update to the latest version or disable the plugin to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share