CVE-2024-1093
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 5, 2024
Updated: Dec 23, 2024
CWE ID 502
Summary
CVE-2024-1093 is a vulnerability affecting the Change Memory Limit plugin for WordPress. The issue arises from a missing capability check on the admin_logic() function, which can be hooked via admin_init. Consequently, unauthenticated attackers can exploit this vulnerability and manipulate the memory limit setting, posing a significant security risk. This issue is present in all versions of the plugin up to and including 1.0. Users are urged to update the plugin to the latest version or remove it if it's no longer needed to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share