CVE-2024-1091

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 29, 2024
Updated: Dec 27, 2024
CWE ID 707
CWE ID 78
CWE ID 74

Summary

CVE-2024-1091 is a vulnerability affecting the ImageRecycle plugin for WordPress. The issue lies in the reinitialize function, which lacks adequate capability checks. As a result, authenticated attackers with subscriber-level access or higher can exploit this flaw to modify plugin data, including deletion of all plugin information. This vulnerability poses a significant risk and requires immediate attention from WordPress site administrators using the ImageRecycle plugin, particularly those still on versions 3.1.13 and below.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share