CVE-2024-11350

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 8, 2025
CWE ID 640

Summary

CVE-2024-11350 is a privilege escalation vulnerability affecting the AdForest theme for WordPress. The issue lies in the theme's failure to validate user identities before updating passwords via the adforest_reset_password() function. Unauthenticated attackers can exploit this flaw to alter any user's password, including administrators. Successful attacks enable attackers to gain administrator access, resulting in potential data breaches or further system compromise. Users are urged to update the AdForest theme to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share