CVE-2024-1178

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 5, 2024
Updated: Jan 8, 2025
CWE ID 121
CWE ID 787

Summary

CVE-2024-1178 is a vulnerability affecting the SportsPress plugin for WordPress, versions 2.7.17 and below. The issue lies in the settings_save() function, where a capability check is missing. This oversight enables unauthenticated attackers to manipulate data, specifically the permalink structure, for the sports clubs managed by the plugin. Successful exploitation could result in unauthorized changes to the website's URL structure, potentially leading to misdirection of users or other security concerns. Organizations using this plugin are advised to update to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share