CVE-2024-11848

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Jan 15, 2025
CWE ID 862

Summary

CVE-2024-11848 is a vulnerability affecting the NitroPack plugin for WordPress. This issue allows authenticated attackers, with subscriber-level access and above, to modify arbitrary options to a fixed value of '1'. Consequently, they can activate certain features, such as user registration, or cause a denial of service condition by modifying other options. The vulnerability stems from a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action, which is present in all versions up to and including 1.17.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share